<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Web Browsing and Associated Traffic Logs in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/web-browsing-and-associated-traffic-logs/m-p/76158#M42192</link>
    <description>&lt;P&gt;Try to play around with "referer" field under URL filtering log to identify what site tried to load blocked content.&lt;/P&gt;</description>
    <pubDate>Mon, 11 Apr 2016 15:14:12 GMT</pubDate>
    <dc:creator>Raido_Rattameister</dc:creator>
    <dc:date>2016-04-11T15:14:12Z</dc:date>
    <item>
      <title>Web Browsing and Associated Traffic Logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/web-browsing-and-associated-traffic-logs/m-p/76154#M42190</link>
      <description>&lt;P&gt;I've never really ran into this issue before and was hoping to get some tips on how you all correlate this type of information.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So we have FQDN host blocks for certain Internet based resources. &amp;nbsp;More and more I'm seeing collateral impacts to unintended websites. &amp;nbsp;(Yes I'm fully aware of how services can be tied together either through associated cloud services providers or even associated name resoulution services.)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My question is how is it that you guys can say from the point of "click" on a link the say "10 entries" in a traffic log are associated with that 1 "click."&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I know that 7.1 has the Unified log function, but I'm still looking for that complete picture.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any help would be appreciated.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Apr 2016 13:59:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/web-browsing-and-associated-traffic-logs/m-p/76154#M42190</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2016-04-11T13:59:54Z</dc:date>
    </item>
    <item>
      <title>Re: Web Browsing and Associated Traffic Logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/web-browsing-and-associated-traffic-logs/m-p/76158#M42192</link>
      <description>&lt;P&gt;Try to play around with "referer" field under URL filtering log to identify what site tried to load blocked content.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Apr 2016 15:14:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/web-browsing-and-associated-traffic-logs/m-p/76158#M42192</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2016-04-11T15:14:12Z</dc:date>
    </item>
    <item>
      <title>Re: Web Browsing and Associated Traffic Logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/web-browsing-and-associated-traffic-logs/m-p/76160#M42193</link>
      <description>&lt;P&gt;So here's the URL log view:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="msn.JPG" style="width: 600px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/3487i9D712890E3C50369/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="msn.JPG" alt="msn.JPG" /&gt;&lt;/span&gt;﻿&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Unfortunately no where does this log say anything about an IP address or the FQDN block totally not associated with MSN that prevented this page from even loading.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Apr 2016 15:27:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/web-browsing-and-associated-traffic-logs/m-p/76160#M42193</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2016-04-11T15:27:35Z</dc:date>
    </item>
    <item>
      <title>Re: Web Browsing and Associated Traffic Logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/web-browsing-and-associated-traffic-logs/m-p/76161#M42194</link>
      <description>&lt;P&gt;Try:&lt;/P&gt;
&lt;P&gt;(referer contains "msn.com") and (action neq alert)&lt;/P&gt;</description>
      <pubDate>Mon, 11 Apr 2016 15:42:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/web-browsing-and-associated-traffic-logs/m-p/76161#M42194</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2016-04-11T15:42:13Z</dc:date>
    </item>
    <item>
      <title>Re: Web Browsing and Associated Traffic Logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/web-browsing-and-associated-traffic-logs/m-p/76163#M42195</link>
      <description>&lt;P&gt;No dice on that search query.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Apr 2016 15:47:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/web-browsing-and-associated-traffic-logs/m-p/76163#M42195</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2016-04-11T15:47:02Z</dc:date>
    </item>
    <item>
      <title>Re: Web Browsing and Associated Traffic Logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/web-browsing-and-associated-traffic-logs/m-p/76168#M42196</link>
      <description>&lt;P&gt;But what happens?&lt;/P&gt;
&lt;P&gt;Users see block page?&lt;/P&gt;
&lt;P&gt;Try to get timeframe when user had issues and find blocked session to identify what was exactly blocked.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Apr 2016 15:53:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/web-browsing-and-associated-traffic-logs/m-p/76168#M42196</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2016-04-11T15:53:48Z</dc:date>
    </item>
    <item>
      <title>Re: Web Browsing and Associated Traffic Logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/web-browsing-and-associated-traffic-logs/m-p/76169#M42197</link>
      <description>&lt;P&gt;*EDIT - Fixed the summary of the last two captures, they needed to be flipped*&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So here's a PCAP from the FW the Rx stage and Drop stage from me going to the site.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Looking at stream 1 that's me trying to go to the site. &amp;nbsp;With the timehack of 15:31:40.123961&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MSN_Rx_CAP.JPG" style="width: 600px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/3488iAB3B950D5BFA2B80/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="MSN_Rx_CAP.JPG" alt="MSN_Rx_CAP.JPG" /&gt;&lt;/span&gt;﻿&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is the drop stage where you can see continual request to the IP occuring at timehack 15:31:40.155869 which again is immediately after the inital web request.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MSN_Drop_CAP.JPG" style="width: 600px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/3489i7F08997C2AD1CF5F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="MSN_Drop_CAP.JPG" alt="MSN_Drop_CAP.JPG" /&gt;&lt;/span&gt;﻿&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is looking at the Rx stage where you can see where the communication to the IP in question for the FQDN drops. &amp;nbsp;This is occuring on stream 20 at 15:31:40.155287, so after the "start" of the web request.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MSN_Rx_CAP2.JPG" style="width: 600px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/3490i4BDF2E4BA61CEAFD/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="MSN_Rx_CAP2.JPG" alt="MSN_Rx_CAP2.JPG" /&gt;&lt;/span&gt;﻿&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So does anyone have a good way to track in some sort of consolidated log without performing a report on a specific user every time this comes up?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Apr 2016 16:02:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/web-browsing-and-associated-traffic-logs/m-p/76169#M42197</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2016-04-11T16:02:25Z</dc:date>
    </item>
    <item>
      <title>Re: Web Browsing and Associated Traffic Logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/web-browsing-and-associated-traffic-logs/m-p/76170#M42198</link>
      <description>&lt;P&gt;So this is stemming from a security policy that I've since had changed, but in essence this was a FQDN drop, so a L3 drop. &amp;nbsp;The original intent was users wouldn't be getting a response page at all. &amp;nbsp;The security team didn't want "callbacks" to malicious domains so there was just a L3 drop rule for specific stuff.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've since gotten this changed where these types of things are getting integatred into a L7 block so users would see a response page.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In short I'm trying to troubleshoot something that I don't foresee being a big issue moving forward, but I'm still curious to understand how understand the academic question of how can I see an "end-to-end" log of a single session so to speak from when a user tries to vist a single page without creating a specific user report.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Apr 2016 16:00:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/web-browsing-and-associated-traffic-logs/m-p/76170#M42198</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2016-04-11T16:00:16Z</dc:date>
    </item>
    <item>
      <title>Re: Web Browsing and Associated Traffic Logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/web-browsing-and-associated-traffic-logs/m-p/76177#M42202</link>
      <description>&lt;P&gt;Yeah you are blocking already at TCP SYN level and it never gets to HTTP GET.&lt;/P&gt;
&lt;P&gt;You can check what you see in traffic log if you filter traffic that goes to&amp;nbsp;64.33.232.56&lt;/P&gt;
&lt;P&gt;Click on the mag glass and check if you see any more details there.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Apr 2016 18:17:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/web-browsing-and-associated-traffic-logs/m-p/76177#M42202</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2016-04-11T18:17:10Z</dc:date>
    </item>
    <item>
      <title>Re: Web Browsing and Associated Traffic Logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/web-browsing-and-associated-traffic-logs/m-p/76179#M42203</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister﻿&lt;/a&gt;&amp;nbsp;I get what you're saying but I'm looking for a straight forward way for an admin to "follow the trail" of a user when they're intiating this traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The only reason I know that this dropped traffic is associated to the web page loading is because I can create policy in the firewall and put my traffic above these FQDN denies. &amp;nbsp;When doing so this destination traffic isn't dropped and the web pages load.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Session IDs (Funny enough there isn't even a session ID for the dropped traffic. &amp;nbsp;To me this seems like where this should be a feature enhancement or something where an admin can correlate a drop to something a user is actually doing.) are different between the URL logs and the traffic logs of the traffic that's being dropped so there's really no way for me to correlate in any fashion, that I can find, a these various logs into something useable which define a single action from a user.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Am I missing something?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Apr 2016 18:30:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/web-browsing-and-associated-traffic-logs/m-p/76179#M42203</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2016-04-11T18:30:02Z</dc:date>
    </item>
    <item>
      <title>Re: Web Browsing and Associated Traffic Logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/web-browsing-and-associated-traffic-logs/m-p/76195#M42207</link>
      <description>&lt;P&gt;What is the reason this traffic is blocked?&lt;/P&gt;
&lt;P&gt;Do you allow traffic to only limited number of ip addresses through FQDN objects in policy destination field?&lt;/P&gt;
&lt;P&gt;If you would block traffic based on URL category then session would be created and you could follow referer field in URL filter log.&lt;/P&gt;
&lt;P&gt;If you throw away traffic based on ip/port then session is not created and that is the reason you don't see session number.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Apr 2016 21:17:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/web-browsing-and-associated-traffic-logs/m-p/76195#M42207</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2016-04-11T21:17:13Z</dc:date>
    </item>
    <item>
      <title>Re: Web Browsing and Associated Traffic Logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/web-browsing-and-associated-traffic-logs/m-p/76209#M42211</link>
      <description>&lt;P&gt;Traffic is blocked because of past spearfishing.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;0 hosts are allowed to the FQDN object.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Item 4 really doesn't provide for any conext within the enviornment for what precipiatetd the original traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've still yet to understand how to track traffic back to specific user actions&lt;/P&gt;</description>
      <pubDate>Tue, 12 Apr 2016 02:35:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/web-browsing-and-associated-traffic-logs/m-p/76209#M42211</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2016-04-12T02:35:35Z</dc:date>
    </item>
  </channel>
</rss>

