URL Logging - Best Practises?

cancel
Showing results for 
Search instead for 
Did you mean: 

URL Logging - Best Practises?

L4 Transporter

What's the recommendation on the best way to configure a Palo Alto to log URLs visited during regular browsing?

We have various categories set to block which are of course logged but I've never quite got my head around the logic of setting something to "alert" when actually I don't want to see it in the URL logs, but I do want it logged - if that makes sense i.e. the URL logs should IMO just be a place to quickly see traffic that is the exception.

3 REPLIES 3

L6 Presenter

Hello Network Admin,

If you really want to monitor each and every users activity than I would suggest to go with alert of all categories. However, it has a tradeoff. If there is too much logging for URL logs than they will start overwriting older logs. You may not have logs for long period of time. If there is a panorama in the network than you wouldnt have to worry about this.

If you do not want to monitor browsing activity than just put certain category in "alert" mode like "arms" , "pornography" ,etc. Do not log URLs for social networking or search engines. Which logs only malicious activities only. That way you will have balanced logging which will help to retain logs for longer duration.

Let me know for additional queries.

Regards

Hardik Shah

answers is depends.

from a security standpoint i would recommend alert for all so you can correlate your traffic.

Without URL logging you may only be able to get the DNS which doesnt' always resolve back correctly if its hosted .

URL logging of all http/https traffic also helps with custom app-id creation and ips signature creation.

As far as not logging social networking i would also advise against that as C2 / Command and Control traffic can go through social media . If your doing SSL decrypt on the box or in the network url category search engines can also reveal alot of info.

Also by logging all traffic we've also identified non standard http traffic and the specfic URI

From a performance standpoint obviously not recommended to log everything.

L3 Networker

I personally log everything so i have a record. Then just off load it to our log manager for archive. Just my 2 cents...

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!