how can I generate url logs for an allow rule with url category selected but not url filtering prof?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

how can I generate url logs for an allow rule with url category selected but not url filtering prof?

L4 Transporter

how can I generate url logs for an allow rule with url category selected but not url filtering prof?

 

9 REPLIES 9

Cyber Elite
Cyber Elite

Hello,

Can you elaborate a bit, I'm not sure I understand what your question is. Is your security policy set to log at session end?

 

Please advise,

L4 Transporter

@SThatipelly You can not. URL logs are only generated by the URL fitleing profile. If you need URL log for the rule, keep the URL match conditiona, but also apply URL filtering profile with cusotmer category mathcing your URLs and ation set to "alert"? This will work even if you don't have URL filtering license. 

 

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClKvCAK

@BatD Doesn't that allow traffic to all alert categories?

@OtakarKlier  Sorry for my poor explanation. I want to allow few users to tinyurl.com and block everyone else. Also, I would like to see their allowed attempts logged in url filtering logs. I am trying to configure this rule so it would only allow access to that specific website and log urls.

 

 

@SThatipelly If I understand correctly, you already have URL in the policy match condtion under "Service/URL Categorie" tab. 

If you do, only the traffic matching those categories will be allowed and the URL filtering profile is only applied to allowed trafic. 

@BatD Interesting. I'll try this on a test machine and let you know if it works.

thanks.

this works partially. Good news is the rule is looking at just the website in 'service/url category' but  is blocking the access as the url is in blocklist in the url filtering profile.

In short, the rule is looking at the 'service/url category' field but allowing/denying based on the url filtering profile.

As mentioned, you need to add your URL in Custom URL category and set the action to "Alert". 

@BatD Yeah. I hate to do hat but I think that's the only option left for me.

thanks. for the response.

  • 7040 Views
  • 9 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!