- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
11-15-2018 02:50 AM
Hi,
I applied the default "basic file blocking" profile to the policy that allows users to access the Internet.
In the "Data Filtering" monitor I can see few files being blocked (EXE files for example), but I can't see the full URL of that file (the "File URL" column is all blank).
The goal is to understand if the root URL can be white-listed.
Could you please help ?
Thank you
Alessio
11-15-2018 09:40 AM - edited 11-15-2018 09:40 AM
Hello,
In the Unified logs view you can add the URL column by howvering your mouse over any of hte fileds and waiting for the down arrow, then just follow the path. Another thing to look at would be the maginfying glass icon on the far left of the logs, those will show the different parts of hte session.
Hope that helps.
11-16-2018 02:01 AM
Hi Otakar,
unfortunately, none of the proposed solutions worked: I am still seeing empty columns.
Thank you !
AM
11-16-2018 08:07 AM
Hello,
Sorry about that, after you replied I check my logs and saw the same thing. Since you are looking for safe domains, I would make sure you have the following enabled:
URL Filtering
Wildfire
AV/Threat
If all those are configured properly then probably the domain is most likely safe.
Hope that helps.
02-10-2020 03:49 AM
old post, but it appeared first in my google search for this issue
If you disable the "Log container page only" setting under the profile(s) you use under Objects - Security Profiles - URL Filtering you should see the File URLs in the Data filtering logs. This will also cause a substantial increase in URL filtering logs...
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!