- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
12-27-2016 10:59 PM
Hi Experts,
I am quite new to Palo Alto and I have some queries regarding the URL filter log retention, before we can generate user activty reports for browsed URLs for more than two weeks old, but now we can only see URL filter logs up to no more than 4 days.
What affects the log retention period and how can we generate a month old User Activity report for a specific user if logs are not present anymore.
12-29-2016 11:22 PM
Transfered bytes are irrelevant for logging. Log entries are generated per session so look at seesions counter values. A single http download session which transfer 3Gb means one log entry same as a DNS query for this site which transfers only few bytes.
Check the most used rules and see if you log some non relevant sessions like DNS and ICMP or boradcast traffic and similar.
12-29-2016 11:34 PM
Reports are basicaly queries on log files for specific information. So they are sort of an extract of log files. And I believe they are stored seperately from log files so they don't affect log retention directly.
12-29-2016 11:52 PM
Hi @Ernest_James,
That's possible. ACC got a major facelift in PAN-OS 7.0 and some features were added. Possibly pre-7.0 won't have it.
It will basically return the same output as seen in the Reports>Traffic Reports>Security Rules. As santonic already pointed out you need to check the number of sessions.
Cheers !
-Kim.
01-04-2017 04:21 AM
Even if it's been there always you can optimise it and turn off logging for non interesting traffic.
But to find the source of spike of events: PA FW saves these reports daily. I guess you have to check past reports, find out on which day there was a spike, which rule recorded it and (in the unlikely case you still have logs for that day) you can find out which traffic caused it. If you don't have logs you can check other automated reports and look for possible causes.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!