User ID logs contain IP address-to-username mappings, authentication timestamps, the sources of the IP-to-username mappings, and so forth.
Next-generation firewalls can be configured to perform IP-to-username mappings for a network session. This mapping requires a variety of techniques so that users in all locations, regardless of access method or operating system, can be identified by the firewall. In addition to allowing the firewall to map an IP address to a username, this integration also allow the firewall to recognize when a user has logged in or logged out of a networked resource.
User-ID logs are generated whenever a user authentication event occurs using a resource to which the firewall has visibility. For example, a User-ID agent can be installed on the network so that the firewall has visibility to authentication events on domain controllers, Microsoft Exchange servers, or even Windows clients.
See the following for information related to supported log formats:
(AUTH COMPLETION TIME)
Time when the authentication was completed. This string contains a timestamp value that is the number of microseconds since the Unix epoch.
CEF field name: end
EMAIL field name: AuthCompletionTime
HTTPS field name: AuthCompletionTime
LEEF field name: AuthCompletionTime
(COUNT OF REPEATS)
(CORTEX DATA LAKE TENANT ID)
(DG HIERARCHY LEVEL 1)
(DG HIERARCHY LEVEL 2)
(DG HIERARCHY LEVEL 3)
(DG HIERARCHY LEVEL 4)
(IS DUPLICATE LOG)
(IS PRISMA NETWORKS)
(IS PRISMA USERS)
(MAPPING DATA SOURCE TYPE)
Time when the log was generated on the firewall's data plane. This string contains a timestamp value that is the number of microseconds since the Unix epoch.
CEF field name: start
EMAIL field name: TimeGenerated
HTTPS field name: TimeGenerated
LEEF field name: devTime
(TIME GENERATED HIGH RESOLUTION)
Time the log was generated in data plane with millisec granularity in format YYYY-MM-DDTHH:MM:SS[.DDDDDD]Z.
CEF field name: PanOSTimeGeneratedHighResolution
EMAIL field name: TimeGeneratedHighResolution
HTTPS field name: TimeGeneratedHighResolution
LEEF field name: TimeGeneratedHighResolution
(USER IDENTIFIED BY SOURCE)
Recommended For You
Recommended videos not found.