<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to forward traffic (URL) to a syslog server? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-forward-traffic-url-to-a-syslog-server/m-p/3531#M2604</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;URL logs are actually threat logs, listed as informational severity (as in the screenshot at the bottom of the page you linked). When you send the informational severity threat logs, that will contain the URL if you supply the $misc token.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Greg&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 14 Apr 2015 23:15:37 GMT</pubDate>
    <dc:creator>gwesson</dc:creator>
    <dc:date>2015-04-14T23:15:37Z</dc:date>
    <item>
      <title>How to forward traffic (URL) to a syslog server?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-forward-traffic-url-to-a-syslog-server/m-p/3530#M2603</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The $misc variable can only be used for Threats?&lt;/P&gt;&lt;P&gt;How to register the URL in syslog server?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CEF Key Name: &lt;STRONG&gt;request&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Full Name: &lt;STRONG&gt;requestURL&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Data Type: &lt;STRONG&gt;string&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Length: &lt;STRONG&gt;1024&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Meaning: &lt;STRONG&gt;URL or filename for &lt;SPAN style="text-decoration: underline;"&gt;threat&lt;/SPAN&gt; logs&lt;/STRONG&gt; &lt;/P&gt;&lt;P&gt;Palo Alto Networks Value Field: &lt;STRONG&gt;$mis&lt;/STRONG&gt;c&lt;/P&gt;&lt;P&gt;&lt;EM&gt;from&lt;/EM&gt; &lt;A _jive_internal="true" href="/servlet/JiveServlet/previewBody/7088-102-3-24932/Palo Alto Networks_PANOS_6_0_CEF_Configuration Guide_2014.pdf"&gt;PANOS_6_0_CEF_Configuration&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-3964"&gt;How to Forward Custom URL Logs to a Syslog Server&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Apr 2015 15:48:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-forward-traffic-url-to-a-syslog-server/m-p/3530#M2603</guid>
      <dc:creator>UNIVALI</dc:creator>
      <dc:date>2015-04-14T15:48:28Z</dc:date>
    </item>
    <item>
      <title>Re: How to forward traffic (URL) to a syslog server?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-forward-traffic-url-to-a-syslog-server/m-p/3531#M2604</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;URL logs are actually threat logs, listed as informational severity (as in the screenshot at the bottom of the page you linked). When you send the informational severity threat logs, that will contain the URL if you supply the $misc token.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Greg&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Apr 2015 23:15:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-forward-traffic-url-to-a-syslog-server/m-p/3531#M2604</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2015-04-14T23:15:37Z</dc:date>
    </item>
  </channel>
</rss>

