Monitoring Web Activity (Strata Cloud Manager)
Focus
Advanced URL Filtering

Monitoring Web Activity (Strata Cloud Manager)

Table of Contents


Monitoring Web Activity (Strata Cloud Manager)

The following list describes Strata Cloud Manager features that provide rich URL filtering and web activity data or serve as important tools for finding, analyzing, or sharing this data. To learn more about a specific feature, click on the corresponding link.
  • The Strata Command Center is the homepage of Strata Cloud Manager and aggregates data from various sources to provide a high-level view of the operational health, data security, and threats across your Prisma Access and NGFW deployments.
  • You can view consolidated data on network traffic, URL, application usage, threats, and user activity from this dashboard, which features visualization, monitoring, and reporting capabilities. Activity Insights shows aggregated data per Strata Logging Service tenant deployed in Prisma Access and NGFW environments.
    The dashboards (tabs) to prioritize for URL filtering and web activity monitoring are as follows:
    • Overview—View the summary of most seen applications, threats, users, URLs, and rules in your network for the selected time period. Glance through this view to quickly identify any irregularities within your network and then delve deeper to examine the activity that requires investigation.
    • Threats—A holistic view of all threats that Advanced URL Filtering and other Palo Alto Networks security services detected and blocked in your network. You can view threat trends, impacted applications, users, and Security policy rules that are allowing or blocking threats.
    • Applications—See an overview of the applications on your network, including their risk, sanction status, bandwidth consumed, and the top users of these applications.
    • Users—See individual users’ browsing patterns: their most frequently visited sites, the sites with which they’re transferring data, and attempts to access high-risk sites. The data from your URL Filtering logs and the Cloud Identity Engine enable this visibility.
      To access user activity data and share reports easily and securely, we recommend activating and configuring the Cloud Identity Engine.
    • Rules—View the Security policy rules that are matched against all the traffic in your network. Review the most matched rules to the traffic sessions, analyze those sessions to understand if the rule is overly permissive and optimize the rule if needed.
  • Your logs provide an audit trail for system, configuration, and network events. Jump from an Activity dashboard to your logs, filter by URLs to get details and investigate findings.
  • Use the search on Strata Cloud Manager and enter a security artifact (an IP address, domain, URL, or file hash) to interact with data just for that artifact, drawn from both your network and global threat intelligence findings. For example, you can search an IP address to view the total number of times the IP address was detected over the past 30 days.
  • View predefined reports and options for scheduling reports, downloading, and sharing a report at any time for offline viewing. The following reports are most relevant to URL filtering:
    • Activity Insights - Summary
    • App Usage Report
    • Executive Summary
    • User Activity