To obtain IP address-to-username mappings from existing
network services that authenticate users, you can configure the
PAN-OS integrated User-ID agent or Windows-based User-ID agent to
parse
Syslog messages
from those services. To keep user mappings up to date, you can also configure
the User-ID agent to parse syslog messages for logout events so
that the firewall automatically deletes outdated mappings.