__telemetryuser System Account
PAN-OS uses the permanent __telemetryuser system account to collect and upload device
telemetry data securely without requiring any administrator configuration.
| Where Can I Use This? | What Do I Need? |
- NGFW (Managed by Strata Cloud Manager)
- NGFW (Managed by PAN-OS or Panorama)
|
For Strata Cloud Manager managed NGFWs:
Telemetry autoenablement feature requires PAN-OS 10.2.17, 11.1.11,
11.2.8, 12.1.2, and later releases.
|
The __telemetryuser account is a permanent, system-generated local
administrator account that PAN-OS uses to execute internal commands required for Device
Telemetry data collection. You do not need to create, manage, or configure this
account.
The __telemetryuser account is present on the system regardless of
whether you enable or disable Device Telemetry. If you delete the account, PAN-OS
recreates it during the next system reboot. To manage telemetry settings, select
Tenant Management on the hub, or select in Strata Cloud Manager.
Telemetry Account Visibility
You can view the __telemetryuser account in the following locations
in the web interface:
- The Logged in Admins section of the dashboard during active collection
cycles
Both behaviors are expected. To protect your system security, the account cannot log
in externally, execute interactive commands, or perform configuration changes.
Telemetry Account Version History
PAN-OS introduced the __telemetryuser account to permanently replace
the legacy transient _cliuser account, which PAN-OS created and
deleted during each collection cycle. Transitioning to a permanent account improves
telemetry collection reliability.
The account is available in the following releases:
- PAN-OS 10.2.18, PAN-OS 10.2.20, and later releases
- PAN-OS 11.1.10-h12, PAN-OS 11.1.12, and later releases
- PAN-OS 11.2.4-h14, PAN-OS 11.2.7-h4, PAN-OS 11.2.10, PAN-OS 11.2.11, and
later releases
- PAN-OS 12.1.4-h3, PAN-OS 12.1.5, PAN-OS 12.1.8, and later releases
- PAN-OS 12.2.0 and later releases
Telemetry Collection Behavior
To collect telemetry data, the __telemetryuser account executes
predefined, read-only command-line interface (CLI) commands and queries, compresses
the output into a .tgz bundle, and uploads the bundle to the
secure Palo Alto Networks® endpoint.
PAN-OS uploads bundles at the following predefined intervals:
- Minute interval: Executes every five minutes in PAN-OS 11.0 and later
releases, or every 20 minutes in releases earlier than PAN-OS 11.0.
- Hour interval: Executes every 60 minutes.
- Day interval: Executes every 24 hours.
Security Considerations
The __telemetryuser account incorporates the following security
design controls:
- Privileges: The account operates with limited, read-only privileges
required strictly for telemetry data collection and script execution. It does
not possess superuser or elevated administrative permissions.
- Interactive access: The account does not support interactive login. You
cannot use it to log in through Secure Shell (SSH), the web interface, or an
application programming interface (API).
- Configuration changes: The account is architecturally incapable of making
configuration changes.
- Disabled telemetry: The __telemetryuser account remains
on the system even if you disable Device Telemetry. If you manually delete the
account, PAN-OS recreates it during the next reboot to maintain consistent
system behavior.
Frequently Asked Questions
Is __telemetryuser a security risk?
No. The account is restricted to internal, read-only command execution. It
cannot log in externally or make configuration changes.
Can you delete __telemetryuser?
Do not delete the account. If you delete the account while Device Telemetry
is enabled, the device sends empty bundles, which causes issues in
telemetry-related services. Additionally, PAN-OS® recreates the account
during the next system reboot. To stop data collection, select and disable Device Telemetry. The
__telemetryuser account remains on the system
regardless of your telemetry configuration.
Why did this account appear after a PAN-OS upgrade?
When you upgrade to a PAN-OS® release that contains the fix for
PAN-292447, the upgrade permanently adds the
__telemetryuser account. In PAN-OS releases earlier
than PAN-OS 10.2.18, PAN-OS 11.1.10-h12, PAN-OS 11.2.4-h14, and PAN-OS
12.1.4-h3, the legacy transient _cliuser account performed
the same telemetry collection functions.
Why does __telemetryuser appear in Logged in Admins?
The account appears briefly during active collection cycles. This is expected
behavior and does not indicate unauthorized external access.