Usernames Missing in Traffic Logs After Enabling Panorama User-ID Redistribution

Usernames Missing in Traffic Logs After Enabling Panorama User-ID Redistribution

158
Created On 07/29/26 01:40 AM - Last Modified 07/29/26 01:46 AM


Symptom


  • User-ID redistribution enabled from Panorama

  • User-to-IP mapping populates on local firewalls (verified via CLI command >show user ip-user-mapping all)

  • Source User column in traffic logs displays only IP addresses instead of usernames



Environment


  • on-prem firewalls
  • Panorama
  • User-ID Redistribution


Cause


User-ID processing is disabled on the source security zone where user traffic originates. The firewall only maps IP addresses to usernames for traffic originating from zones with User-ID explicitly enabled.



Resolution


Local Firewall Management:

  1. Log into the firewall WebUI.

  2. Navigate to Network > Zones.

  3. Select the source zone where user traffic originates.

  4. Select the Enable User-ID checkbox.

  5. Click OK to close the dialog box.

  6. Click Commit.

Panorama Management:

  1. Log into the Panorama WebUI.

  2. Navigate to Network > Zones (or Templates > Network > Zones).

  3. Select the template or template stack associated with the local firewall.

  4. Select the source zone where user traffic originates.

  5. Select the Enable User-ID checkbox.

  6. Click OK to close the dialog box.

  7. Click Commit and push changes to the target firewall.



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA1Ki000000kCAoKAM&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail