Monitoring Accessed URL's

Reply
Highlighted
L1 Bithead

Monitoring Accessed URL's

Hi Everyone,

We have the URL filtering license, I am trying to log all websites that a user access, however, I noticed PA only logs websites which the user fails to access due to a URL filtering policy, ie only websites that are blocked from the user because they fall under a blocked category.

Is there a way to log user access to all URL's.

Thanks

L7 Applicator

Re: Monitoring Accessed URL's

You can get them to log by changing the category from allow to alert.

But be careful what you ask for, this will generate a lot of logs and reduce your overall logging time period as logs roll over when space is used up.

Steve Puluka BSEET - IP Architect - DQE Communications (Metro Ethernet/ISP)
ACE PanOS 6; ACE PanOS 7; ASE 3.0; PSE 7.0 Foundations & Associate in Platform; Cyber Security; Data Center
L5 Sessionator

Re: Monitoring Accessed URL's

Firewall will log the blocked website. But if you want to log the website that users have visited you have to set the action to alert for all URL category.

L6 Presenter

Re: Monitoring Accessed URL's

This is where Palo is doing a disservice to it's customer base.  I'm not certain where this premise that "We should only log things that we want to deny" came from.  The firewall is a security appliance.  A device used for usage audit history and compliance verification. 

It's annoying when I call into TAC and I get the same spiel from them about "Logging on session start"...well you know that is going to create a lot of logs.  Since when is more information a bad thing?  Using a firewall as it's intended wouldn't administrators need to be able to track back a source of infection? 

If we're blocking every malicious thing from the beginning and nothing ever is miscategorized, not caught, or users never do anything bad then sure we don't need to log the "allowed" stuff.  But we live in the real world.  Where things are missed, malware gets by and users don't do what we want them to.  It kind of difficult to triage incidents retroactively when there isn't even a log of the even occurring.

Sorry this didn't answer the question (it already has been), but it seems in general more and more comments are about "not logging" to reduce the performance hit or log retention when what should happen is administrators should bake these concerns into the original architecture and deploy a solution taking these concerns in mind.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!