I cannot get user authentication information to go to my syslog server so Palo alto can parse the logs for the username/IP. I've tried multiple settings for the controller for logging. Under what category/subcategory do I use to get the information? What logging level?
current effort:
User category / dot1x & radius subcategory with logging level informational for both.
Under the logging servers area, I have category User with severity informational.
Any help will be greatly appreciated.