<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: URL logs missing for Traffic through alert only URL category / profile. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/url-logs-missing-for-traffic-through-alert-only-url-category/m-p/589410#M117475</link>
    <description>&lt;P&gt;Please share any details you receive from TAC as they might be helpful for future users. Thanks!&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 12 Jun 2024 22:15:00 GMT</pubDate>
    <dc:creator>JayGolf</dc:creator>
    <dc:date>2024-06-12T22:15:00Z</dc:date>
    <item>
      <title>URL logs missing for Traffic through alert only URL category / profile.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-logs-missing-for-traffic-through-alert-only-url-category/m-p/589369#M117465</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;TABLE&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD class="label"&gt;Software Version&lt;/TD&gt;
&lt;TD class="data"&gt;11.1.2-h3&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have a strange situation: Some URL filtering log entries for valid visits to web sites are missing. The traffic goes through a security rule which has a URL filtering profile with only alert and block categories. We have both Pan-db and Advanced URL filtering licenses.&amp;nbsp; &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We can see the traffic in the main traffic log but no corresponding entry in the URL filtering log.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Strangely though, if we create a custom URL category with the web site in question added and then set that to alert in the URL profile then the URL log appears. if you remove it from the custom url category and browse to the web site. URL filtering log doesn't show the relevant entry.&lt;/P&gt;
&lt;P&gt;I have come across at least one other community entry on a similar case.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any help would be welcome. Just waiting for TAC to get involved.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jun 2024 13:06:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-logs-missing-for-traffic-through-alert-only-url-category/m-p/589369#M117465</guid>
      <dc:creator>uduwawalan</dc:creator>
      <dc:date>2024-06-12T13:06:26Z</dc:date>
    </item>
    <item>
      <title>Re: URL logs missing for Traffic through alert only URL category / profile.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-logs-missing-for-traffic-through-alert-only-url-category/m-p/589409#M117474</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11933"&gt;@uduwawalan&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm wondering if the websites that aren't populating in the URL filtering logs are properly categorized. If you check&amp;nbsp;&lt;A href="https://urlfiltering.paloaltonetworks.com/" target="_blank"&gt;https://urlfiltering.paloaltonetworks.com/&lt;/A&gt;&amp;nbsp;and enter the websites that aren't populating. Do they come up with a category that you specified as "alert" within your URL filtering profile?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jun 2024 22:13:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-logs-missing-for-traffic-through-alert-only-url-category/m-p/589409#M117474</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2024-06-12T22:13:18Z</dc:date>
    </item>
    <item>
      <title>Re: URL logs missing for Traffic through alert only URL category / profile.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-logs-missing-for-traffic-through-alert-only-url-category/m-p/589410#M117475</link>
      <description>&lt;P&gt;Please share any details you receive from TAC as they might be helpful for future users. Thanks!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jun 2024 22:15:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-logs-missing-for-traffic-through-alert-only-url-category/m-p/589410#M117475</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2024-06-12T22:15:00Z</dc:date>
    </item>
    <item>
      <title>Re: URL logs missing for Traffic through alert only URL category / profile.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-logs-missing-for-traffic-through-alert-only-url-category/m-p/589527#M117489</link>
      <description>&lt;P&gt;Thanks.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes they are being categorized as the websites are quite standard ones that we are testing. for example "Marksand spencer.com" or qad.com or oracle.com which are well known web sites and are categorized if you run the command test url "......." in the CLI of the box. It's quite strange.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I just put in a test policy targeting a test workstation with a URL profile that had all categories blocked. That just allowed the traffic through. I could see some entries in the traffic log that said "block-url" but they were not relevant to the web sites I was browsing to.&lt;/P&gt;
&lt;P&gt;So I added the these websites to custom category.. They then appeared in the URL log and got blocked but no block message from the Palo box.Just a "site can't be reached" message.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;TAC are apparently reviewing the Techsupport file and other info our support company provided.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The term Rome is burning while nero played violin comes to mind.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Not a very pleasant situation to find yourself in.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jun 2024 13:33:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-logs-missing-for-traffic-through-alert-only-url-category/m-p/589527#M117489</guid>
      <dc:creator>uduwawalan</dc:creator>
      <dc:date>2024-06-13T13:33:15Z</dc:date>
    </item>
    <item>
      <title>Re: URL logs missing for Traffic through alert only URL category / profile.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-logs-missing-for-traffic-through-alert-only-url-category/m-p/589796#M117530</link>
      <description>&lt;P&gt;In the end, no one from TAC contacted us. Our own support provider,observed in the config xml that in case of a few url entries in the url categories, there was a strange set of characters were appended. This set of characters as follows -&amp;nbsp; "&amp;amp;#x200B. Apparently these characters are appended if you inadvertently leave a space at the end of url entry when you add them to url categories when creating customer categories.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So we save a config, exported it out, did a search and replace of all the instances. We then saved the config xml file.Imported the config file and committed the change.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So far all seems fine so far.&lt;/P&gt;
&lt;P&gt;I am very disappointed with Palo TAC. this was a case where quick intervention&amp;nbsp; was necessary and we have managed to fix the problem days after, by ourselves largely.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What is point of paying for support when it's not there when you need it?&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jun 2024 12:59:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-logs-missing-for-traffic-through-alert-only-url-category/m-p/589796#M117530</guid>
      <dc:creator>uduwawalan</dc:creator>
      <dc:date>2024-06-18T12:59:28Z</dc:date>
    </item>
  </channel>
</rss>

