<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: url field in cutom log format ? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/url-field-in-cutom-log-format/m-p/34776#M25524</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Karl,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Under custom log format in syslog profiles for threat, there is no URL field. However, as seen below, 'src' and 'dst' field highlighted below should be the source address and the destination address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="cu-log-frmt.PNG" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/4447_cu-log-frmt.PNG" width="450" /&gt;&lt;/P&gt;&lt;P&gt;When compared to Monitor &amp;gt; Logs &amp;gt; Threat logs,&amp;nbsp; source address would be "attacker" and the destination address would be the "victim". There is a checkbox "Resolve hostname" in the web UI, which will resolve the ip-addresses. However this is restricted to just the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="resolve.PNG" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/4449_resolve.PNG" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you export it to syslog, I believe only the ip-addresses will show up for the threat logs and not the URLs.&lt;/P&gt;&lt;P&gt;Let me know if this explanation helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Parth&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 11 Oct 2012 16:07:59 GMT</pubDate>
    <dc:creator>ppatel</dc:creator>
    <dc:date>2012-10-11T16:07:59Z</dc:date>
    <item>
      <title>url field in cutom log format ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-field-in-cutom-log-format/m-p/34775#M25523</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm trying to customize the log forward to my Syslog.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In syslog server profile / custom log format / threat, I definitely not succeed in finding the right field where visited website urls are stored !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If somebody have an idea ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Karl&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Oct 2012 14:55:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-field-in-cutom-log-format/m-p/34775#M25523</guid>
      <dc:creator>Karl</dc:creator>
      <dc:date>2012-10-11T14:55:39Z</dc:date>
    </item>
    <item>
      <title>Re: url field in cutom log format ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-field-in-cutom-log-format/m-p/34776#M25524</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Karl,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Under custom log format in syslog profiles for threat, there is no URL field. However, as seen below, 'src' and 'dst' field highlighted below should be the source address and the destination address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="cu-log-frmt.PNG" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/4447_cu-log-frmt.PNG" width="450" /&gt;&lt;/P&gt;&lt;P&gt;When compared to Monitor &amp;gt; Logs &amp;gt; Threat logs,&amp;nbsp; source address would be "attacker" and the destination address would be the "victim". There is a checkbox "Resolve hostname" in the web UI, which will resolve the ip-addresses. However this is restricted to just the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="resolve.PNG" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/4449_resolve.PNG" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you export it to syslog, I believe only the ip-addresses will show up for the threat logs and not the URLs.&lt;/P&gt;&lt;P&gt;Let me know if this explanation helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Parth&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Oct 2012 16:07:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-field-in-cutom-log-format/m-p/34776#M25524</guid>
      <dc:creator>ppatel</dc:creator>
      <dc:date>2012-10-11T16:07:59Z</dc:date>
    </item>
    <item>
      <title>Re: url field in cutom log format ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-field-in-cutom-log-format/m-p/34777#M25525</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You have to export&amp;nbsp; the informational level threat logs to syslog in order to get the URL logs, having said that if you use the default syslog format then you will get all the fields including the URL field you are looking for as shown below.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Capture1.PNG" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/4450_Capture1.PNG" width="450" /&gt;&lt;/P&gt;&lt;P&gt;You can see the URL www.evernote.com in the above pic. With regards to custom format, Try exporting only $category and $domain in order to get only URL's and their category&amp;nbsp; in the syslog.&lt;IMG alt="Capture2.PNG" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/4451_Capture2.PNG" width="450" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Oct 2012 17:39:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-field-in-cutom-log-format/m-p/34777#M25525</guid>
      <dc:creator>sdurga</dc:creator>
      <dc:date>2012-10-11T17:39:24Z</dc:date>
    </item>
    <item>
      <title>Re: url field in cutom log format ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-field-in-cutom-log-format/m-p/34778#M25526</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Tested this on my box and works as expected &lt;/P&gt;&lt;P&gt;&lt;IMG alt="Capture9.PNG" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/4455_Capture9.PNG" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let us know if u need more info.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tx,&lt;/P&gt;&lt;P&gt;Sandeep T&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Oct 2012 18:18:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-field-in-cutom-log-format/m-p/34778#M25526</guid>
      <dc:creator>sdurga</dc:creator>
      <dc:date>2012-10-11T18:18:29Z</dc:date>
    </item>
    <item>
      <title>Re: url field in cutom log format ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-field-in-cutom-log-format/m-p/34779#M25527</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On my box runnig v4.1.7, the field $domain always returns value 1 &lt;img id="smileysad" class="emoticon emoticon-smileysad" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-sad.png" alt="Smiley Sad" title="Smiley Sad" /&gt;&lt;/P&gt;&lt;P&gt;Finaly I found that urls are stored in filed $misc !!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By the way, I noticed that urls on port 80 are stored entirely, whereas for the urls on port https 443 only the left part is stored&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Oct 12 11:01:13 business-and-economy 1 "batellerie.org/images/thumbs/logo_site_batellerie_org.png" (port 80) -&amp;gt; works fine&lt;/P&gt;&lt;P&gt;Oct 12 11:01:47 social-networking 1 "3-ect.channel.facebook.com/" (port 443) -&amp;gt; nothing after the slash&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards, &lt;/P&gt;&lt;P&gt;Karl&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Oct 2012 09:07:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-field-in-cutom-log-format/m-p/34779#M25527</guid>
      <dc:creator>Karl</dc:creator>
      <dc:date>2012-10-12T09:07:45Z</dc:date>
    </item>
    <item>
      <title>Re: url field in cutom log format ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-field-in-cutom-log-format/m-p/34780#M25528</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is expected behavior, URL's for the port 443 is derived from the certificate common name, because it is an SSL connection so we do not have the visibility into http get requests so we make use of the SSL certificate common name for finding the website name. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tx,&lt;/P&gt;&lt;P&gt;Sandeep T&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Oct 2012 15:25:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-field-in-cutom-log-format/m-p/34780#M25528</guid>
      <dc:creator>sdurga</dc:creator>
      <dc:date>2012-10-12T15:25:38Z</dc:date>
    </item>
    <item>
      <title>Re: url field in cutom log format ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-field-in-cutom-log-format/m-p/34781#M25529</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your answer. Do you think that with a decryption policy enabled, the entire url would be displayed ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Karl&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Oct 2012 15:16:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-field-in-cutom-log-format/m-p/34781#M25529</guid>
      <dc:creator>Karl</dc:creator>
      <dc:date>2012-10-15T15:16:19Z</dc:date>
    </item>
  </channel>
</rss>

