We are trying to produce a report which summarizes the URLs visited by a specific user along with the total bytes downloaded from each URL.
It seems that the bytes are available in the Traffic log, but not the URLs; conversely, the URLs are in the URL log, but not the bytes.
Is there some way or producing reports which correlate the various logs?
I'm trying to do the same.
I'm exporting both the traffic and url logs to another device and trying to create a more comprehensive log file with both the URL and bytes fields.
Once all this info is in one log file hopefuly I will be able to do some analysis on it.
There are a number of fields you can use to reliably match up the log entries - session ID, src & dst IP, src & dst port etc.
My attempts at writing a shell script to merge the url and traffic files show promise but are pitifully slow. I can't help feeling that there is a better way than a shell script to do this - but an even better way would be for all the info to be in one log file to start with!
I can't imagine it's all that difficult to just allow the various logs to be combined into a single report query right on the device. There is potentially a lot of valuable information to be leveraged from correlating the separate logs.
I hope this is something that PAN is already working on.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!