Palo Alto Networks Certified Network Security Engineer (PCNSE)TroubleshootEasy
A company is experiencing issues with User-ID where some users are not being correctly mapped to their IP addresses, leading to incorrect policy enforcement. The domain controller logs show successful authentication, but the firewall's User-ID logs are inconsistent. The administrator wants to verify if the User-ID agent is receiving all necessary security event logs from the domain controller. Which type of log should the administrator specifically look for on the domain controller to confirm the agent's access to user authentication events?
- ASecurity logs
- BSystem logs
- CApplication logs
- DDirectory Service logs
Show answer & explanationAnswer & explanation
Correct answer: A. Security logs
User-ID agents primarily rely on Windows Security Event logs (specifically Event IDs like 4624 for successful logon) from domain controllers to map users to their IP addresses. Incorrect access to these logs will prevent proper User-ID functionality.
Why the other options are wrong
- B. System logs contain general system events, not user authentication events relevant to User-ID.
- C. Application logs contain events from applications, not user authentication events relevant to User-ID.
- D. Directory Service logs relate to Active Directory operations, not direct user authentication events for User-ID.
User-ID Log Source
Palo Alto Networks User-ID agents primarily gather user-to-IP mappings by monitoring Windows Security Event logs on domain controllers.
- Monitors Event ID 4624 (successful logon).
- Requires appropriate permissions for the User-ID agent service account.
- Key for accurate policy enforcement based on users.
Memory trick: Security logs secure the user's ID.