<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: how to monitor web activity using domain name. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-monitor-web-activity-using-domain-name/m-p/222335#M63948</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/76179"&gt;@AzerbaijanSupermarkets&lt;/a&gt;&lt;/P&gt;&lt;P&gt;As mentionned by &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;, in my eyes this is a job for an email relay/gateway server, not really for a firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(Except maybe if FR 1255 sometimes will be implemented? &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;: what exactly is this FR about? Logging of sender and receipient in smtp connections?)&lt;/P&gt;</description>
    <pubDate>Sun, 15 Jul 2018 16:48:23 GMT</pubDate>
    <dc:creator>Remo</dc:creator>
    <dc:date>2018-07-15T16:48:23Z</dc:date>
    <item>
      <title>how to monitor web activity using domain name.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-monitor-web-activity-using-domain-name/m-p/222151#M63903</link>
      <description>&lt;P&gt;Good day to everyone!&lt;/P&gt;&lt;P&gt;I have such a case: I have to find out which users send email to ecober.com.&lt;/P&gt;&lt;P&gt;I have researched, but couldn't find any useful information.&lt;/P&gt;&lt;P&gt;Which filters should I use in monitor tab?&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jul 2018 08:04:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-monitor-web-activity-using-domain-name/m-p/222151#M63903</guid>
      <dc:creator>AzerbaijanSupermarkets</dc:creator>
      <dc:date>2018-07-13T08:04:05Z</dc:date>
    </item>
    <item>
      <title>Re: how to monitor web activity using domain name.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-monitor-web-activity-using-domain-name/m-p/222216#M63916</link>
      <description>&lt;P&gt;you can reach out to your local sales team and have them add your vote to&amp;nbsp; Feature Request FR 1255&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jul 2018 13:53:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-monitor-web-activity-using-domain-name/m-p/222216#M63916</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-07-13T13:53:12Z</dc:date>
    </item>
    <item>
      <title>Re: how to monitor web activity using domain name.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-monitor-web-activity-using-domain-name/m-p/222223#M63920</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/76179"&gt;@AzerbaijanSupermarkets&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Generally one would look up the MX records for ecober.com (currently 173.203.187.1 and 173.203.187.2) and then you could utilize that within your search. The issue that you'll run into however is that the user is likely going through a relay server and won't actually show as 'source-user x connected to 173.203.187.1' from the firewall. This is where logging on your email server or email gateway will have to be reviewed and you'll have to see which users actually sent emails to 'ecober.com' or the addresses recorded in their MX record.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hopefully that helps.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jul 2018 14:21:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-monitor-web-activity-using-domain-name/m-p/222223#M63920</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-07-13T14:21:37Z</dc:date>
    </item>
    <item>
      <title>Re: how to monitor web activity using domain name.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-monitor-web-activity-using-domain-name/m-p/222228#M63923</link>
      <description>&lt;P&gt;Would it be possible to identify the recipient domain in a custom app&amp;nbsp;by matching smtp-req-argument?&lt;/P&gt;&lt;P&gt;Then simply&amp;nbsp;report on&amp;nbsp;that application&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jul 2018 14:37:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-monitor-web-activity-using-domain-name/m-p/222228#M63923</guid>
      <dc:creator>JoeAndreini</dc:creator>
      <dc:date>2018-07-13T14:37:01Z</dc:date>
    </item>
    <item>
      <title>Re: how to monitor web activity using domain name.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-monitor-web-activity-using-domain-name/m-p/222335#M63948</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/76179"&gt;@AzerbaijanSupermarkets&lt;/a&gt;&lt;/P&gt;&lt;P&gt;As mentionned by &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;, in my eyes this is a job for an email relay/gateway server, not really for a firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(Except maybe if FR 1255 sometimes will be implemented? &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;: what exactly is this FR about? Logging of sender and receipient in smtp connections?)&lt;/P&gt;</description>
      <pubDate>Sun, 15 Jul 2018 16:48:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-monitor-web-activity-using-domain-name/m-p/222335#M63948</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-07-15T16:48:23Z</dc:date>
    </item>
    <item>
      <title>Re: how to monitor web activity using domain name.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-monitor-web-activity-using-domain-name/m-p/222359#M63953</link>
      <description>&lt;P&gt;Thank you all for your replies.&lt;/P&gt;&lt;P&gt;Yes, we made this report using our local mail server.&lt;/P&gt;&lt;P&gt;But, we can't filter other mail applications (like gmail, yahoo and etc.).&lt;/P&gt;&lt;P&gt;This is still an issue.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jul 2018 06:14:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-monitor-web-activity-using-domain-name/m-p/222359#M63953</guid>
      <dc:creator>AzerbaijanSupermarkets</dc:creator>
      <dc:date>2018-07-16T06:14:02Z</dc:date>
    </item>
    <item>
      <title>Re: how to monitor web activity using domain name.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-monitor-web-activity-using-domain-name/m-p/222373#M63956</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&amp;nbsp;
&lt;P&gt;(Except maybe if FR 1255 sometimes will be implemented? &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;: what exactly is this FR about? Logging of sender and receipient in smtp connections?)&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;FR1255 requests to add sender and receiver email address in the threat logs&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jul 2018 10:47:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-monitor-web-activity-using-domain-name/m-p/222373#M63956</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-07-16T10:47:34Z</dc:date>
    </item>
  </channel>
</rss>

