10-30-2017 09:24 AM
With the addition of the Command-and-Control URL category, I would love to get an alert any time someone hits that category so we can remediate the problem PC. I just can't for the life of me figure out how to set that up. I don't want all URL category blocks sending alerts, just this one. Before I pull my hair out trying to figure out how to do it I figured I would ask all you smart folks here. Is this even possible?
10-30-2017 11:35 AM
Are you running 8.0.*?
If you go into Log Forwarding you could actually add this pretty easily. Create a new profile match list that specifies the log type as URL, then in the filter simply specify ( category eq command-and-control ). The end result would essentially just be a new match list that looks like below, then this should function fine.
10-30-2017 12:01 PM
I don't think you'll have that as an option then until you move up to 8.0. Depending on your security policy structure you could put a policy above your current browsing policy that specifies that command-and-control traffic gets blocked and put a log-forwarding policy that alerts on URL actions specifically on this new rule.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!