<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Best/Most Efficient way to view exact URLs in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/best-most-efficient-way-to-view-exact-urls/m-p/411078#M92688</link>
    <description>&lt;P&gt;As&amp;nbsp;@Retired Member&amp;nbsp;said you need to set the action to alert. I generally have a URL filtering profile called URL-Alert where most actions are alert so I can monitor what's going on. I find this is very helpful when trying to build a tighter policy as the URL filtering engine allows you to see most FQDNs that are being requested.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Even on an alert profile I always set categories such as phishing, c2, malware et al to block as a layer of protection.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 04 Jun 2021 04:34:36 GMT</pubDate>
    <dc:creator>ethiSEC</dc:creator>
    <dc:date>2021-06-04T04:34:36Z</dc:date>
    <item>
      <title>Best/Most Efficient way to view exact URLs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-most-efficient-way-to-view-exact-urls/m-p/410957#M92679</link>
      <description>&lt;P&gt;We're currently in the process of moving over from Cisco to Palo and are still trying to work through everything.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We currently have a URL profile attached to every policy and the only actions we have on categories are allow and deny. Should we set everything to at least alert so that they would appear in the URL Filtering logs?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there a way to view what URL a client is going to within the threat logs? I know you can see the URL category in the threat logs but I can't find a way to see the actual URL they went to like what is displayed in the URL Filtering logs?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jun 2021 16:59:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-most-efficient-way-to-view-exact-urls/m-p/410957#M92679</guid>
      <dc:creator>bafergel</dc:creator>
      <dc:date>2021-06-03T16:59:28Z</dc:date>
    </item>
    <item>
      <title>Re: Best/Most Efficient way to view exact URLs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-most-efficient-way-to-view-exact-urls/m-p/410960#M92680</link>
      <description>&lt;P&gt;Correction, meant traffic logs instead of threat logs&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jun 2021 17:00:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-most-efficient-way-to-view-exact-urls/m-p/410960#M92680</guid>
      <dc:creator>bafergel</dc:creator>
      <dc:date>2021-06-03T17:00:56Z</dc:date>
    </item>
    <item>
      <title>Re: Best/Most Efficient way to view exact URLs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-most-efficient-way-to-view-exact-urls/m-p/411063#M92684</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/176243"&gt;@bafergel&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You wrote the solution already. To see the urls the clients are going to, you have to set the action in the url filtering profile to alert for all the categories.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Jun 2021 01:39:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-most-efficient-way-to-view-exact-urls/m-p/411063#M92684</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2021-06-04T01:39:31Z</dc:date>
    </item>
    <item>
      <title>Re: Best/Most Efficient way to view exact URLs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-most-efficient-way-to-view-exact-urls/m-p/411078#M92688</link>
      <description>&lt;P&gt;As&amp;nbsp;@Retired Member&amp;nbsp;said you need to set the action to alert. I generally have a URL filtering profile called URL-Alert where most actions are alert so I can monitor what's going on. I find this is very helpful when trying to build a tighter policy as the URL filtering engine allows you to see most FQDNs that are being requested.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Even on an alert profile I always set categories such as phishing, c2, malware et al to block as a layer of protection.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Jun 2021 04:34:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-most-efficient-way-to-view-exact-urls/m-p/411078#M92688</guid>
      <dc:creator>ethiSEC</dc:creator>
      <dc:date>2021-06-04T04:34:36Z</dc:date>
    </item>
  </channel>
</rss>

