- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
01-25-2015 08:00 AM
What's the recommendation on the best way to configure a Palo Alto to log URLs visited during regular browsing?
We have various categories set to block which are of course logged but I've never quite got my head around the logic of setting something to "alert" when actually I don't want to see it in the URL logs, but I do want it logged - if that makes sense i.e. the URL logs should IMO just be a place to quickly see traffic that is the exception.
01-25-2015 09:26 AM
Hello Network Admin,
If you really want to monitor each and every users activity than I would suggest to go with alert of all categories. However, it has a tradeoff. If there is too much logging for URL logs than they will start overwriting older logs. You may not have logs for long period of time. If there is a panorama in the network than you wouldnt have to worry about this.
If you do not want to monitor browsing activity than just put certain category in "alert" mode like "arms" , "pornography" ,etc. Do not log URLs for social networking or search engines. Which logs only malicious activities only. That way you will have balanced logging which will help to retain logs for longer duration.
Let me know for additional queries.
Regards
Hardik Shah
01-26-2015 01:05 PM
answers is depends.
from a security standpoint i would recommend alert for all so you can correlate your traffic.
Without URL logging you may only be able to get the DNS which doesnt' always resolve back correctly if its hosted .
URL logging of all http/https traffic also helps with custom app-id creation and ips signature creation.
As far as not logging social networking i would also advise against that as C2 / Command and Control traffic can go through social media . If your doing SSL decrypt on the box or in the network url category search engines can also reveal alot of info.
Also by logging all traffic we've also identified non standard http traffic and the specfic URI
From a performance standpoint obviously not recommended to log everything.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!