<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic URL Logging - Best Practises? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/url-logging-best-practises/m-p/6358#M4627</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What's the recommendation on the best way to configure a Palo Alto to log URLs visited during regular browsing?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have various categories set to block which are of course logged but I've never quite got my head around the logic of setting something to "alert" when actually I don't want to see it in the URL logs, but I do want it logged - if that makes sense i.e. the URL logs should IMO just be a place to quickly see traffic that is the exception.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 25 Jan 2015 16:00:29 GMT</pubDate>
    <dc:creator>networkadmin</dc:creator>
    <dc:date>2015-01-25T16:00:29Z</dc:date>
    <item>
      <title>URL Logging - Best Practises?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-logging-best-practises/m-p/6358#M4627</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What's the recommendation on the best way to configure a Palo Alto to log URLs visited during regular browsing?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have various categories set to block which are of course logged but I've never quite got my head around the logic of setting something to "alert" when actually I don't want to see it in the URL logs, but I do want it logged - if that makes sense i.e. the URL logs should IMO just be a place to quickly see traffic that is the exception.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 25 Jan 2015 16:00:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-logging-best-practises/m-p/6358#M4627</guid>
      <dc:creator>networkadmin</dc:creator>
      <dc:date>2015-01-25T16:00:29Z</dc:date>
    </item>
    <item>
      <title>Re: URL Logging - Best Practises?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-logging-best-practises/m-p/6359#M4628</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Network Admin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you really want to monitor each and every users activity than I would suggest to go with alert of all categories. However, it has a tradeoff. If there is too much logging for URL logs than they will start overwriting older logs. You may not have logs for long period of time. If there is a panorama in the network than you wouldnt have to worry about this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you do not want to monitor browsing activity than just put certain category in "alert" mode like "arms" , "pornography" ,etc. Do not log URLs for social networking or search engines. Which logs only malicious activities only. That way you will have balanced logging which will help to retain logs for longer duration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know for additional queries.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 25 Jan 2015 17:26:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-logging-best-practises/m-p/6359#M4628</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2015-01-25T17:26:22Z</dc:date>
    </item>
    <item>
      <title>Re: URL Logging - Best Practises?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-logging-best-practises/m-p/6360#M4629</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;answers is depends. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;from a security standpoint i would recommend alert for all so you can correlate your traffic. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Without URL logging you may only be able to get the DNS which doesnt' always resolve back correctly if its hosted . &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;URL logging of all http/https traffic also helps with custom app-id creation and ips signature creation. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As far as not logging social networking i would also advise against that as C2 / Command and Control traffic can go through social media . If your doing SSL decrypt on the box or in the network url category search engines can also reveal alot of info. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also by logging all traffic we've also identified non standard http traffic and the specfic URI&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From a performance standpoint obviously not recommended to log everything. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Jan 2015 21:05:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-logging-best-practises/m-p/6360#M4629</guid>
      <dc:creator>jkim2</dc:creator>
      <dc:date>2015-01-26T21:05:23Z</dc:date>
    </item>
    <item>
      <title>Re: URL Logging - Best Practises?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-logging-best-practises/m-p/6361#M4630</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I personally log everything so i have a record. Then just off load it to our log manager for archive. Just my 2 cents...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Jan 2015 00:36:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-logging-best-practises/m-p/6361#M4630</guid>
      <dc:creator>oklier</dc:creator>
      <dc:date>2015-01-27T00:36:17Z</dc:date>
    </item>
  </channel>
</rss>

