CLI Cheat Sheet: User-ID
Table of Contents
PAN.OS 11.1 & Later
Expand all | Collapse all
-
- Set Commands Introduced in PAN-OS 11.1
- Set Commands Removed in PAN-OS 11.1
- Show Commands Introduced in PAN-OS 11.1
- Set Commands Introduced in PAN-OS 11.2
- Set Commands Changed in PAN-OS 11.2
- Set Commands Removed in PAN-OS 11.2
- Show Commands Introduced in PAN-OS 11.2
- Show Commands Removed in PAN-OS 11.2
CLI Cheat Sheet: User-ID
Use the following commands to perform common User-ID configuration
and monitoring tasks.
To see more comprehensive logging information
enable debug mode on the agent using the
debug user-id log-ip-user-mapping yes
command.
When you are done troubleshooting, disable debug mode using debug user-id log-ip-user-mapping no
.CLI Cheat Sheet:
User-ID |
---|
View all User-ID agents configured to send
user mappings to the Palo Alto Networks device:
|
View how many log messages came in from
syslog senders and how many entries the User-ID agent successfully
mapped:
|
View the configuration of a User-ID agent
from the Palo Alto Networks device:
|
View group mapping information:
|
View all user mappings on the Palo Alto
Networks device: Show user mappings filtered by a username string (if the string includes the domain name, use two backslashes before the username): Show user mappings for a specific IP address: Show usernames:
|
View the most recent addresses learned from
a particular User-ID agent:
|
View mappings from a particular type of
authentication service: where <authentication-service> can
be authenticate , client-cert , directory-server , exchange-server , globalprotect , kerberos , netbios-probing , ntlm , unknown , vpn-client ,
or wmi-probing .For example, to view all
user mappings from the Kerberos server, you would enter the following
command:
|
View mappings learned using a particular
type of user mapping: where <datasource> can
be agent , captive-portal , event-log , ha , probing , server-session-monitor , ts-agent , unknown , vpn-client ,
or xml-api .For example, to view all user
mappings from the XML API, you would enter the following command:
|
Find a user mapping based on an email address:
For
example:
|
Clear the User-ID cache: Clear a User-ID mapping for a specific IP address:
|