Admin Role Configured for Viewing Logs can only view Subnet Addresses instead of IP Addresses

Admin Role Configured for Viewing Logs can only view Subnet Addresses instead of IP Addresses

26671
Created On 09/26/18 13:53 PM - Last Modified 05/31/23 21:46 PM


Resolution


Issues

An admin user is created on the Palo Alto Networks firewall. The role assigned to this new admin user has only Monitor permissions for the WebGUI.

When this new admin user logs in and searches through any type of logs (traffic, threat, URL filtering etc), the source and destination IPs appear as subnet addresses instead of the host IP addresses.

 

Resolution

This is expected behavior for permissions on monitoring (reading) logs only. If the admin user should have permission for viewing the host IP addresses, then the Privacy option in the Admin Role profile must be enabled for that user.

 

owner: aciobanu



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClxbCAC&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language