Advanced URL Filtering
Schedule and Share URL Filtering Reports
Table of Contents
Schedule and Share URL Filtering Reports
Where can I use this? | What do I need? |
---|---|
|
Notes:
|
You can schedule, generate, and share various
reports related to URL filtering and web activity.
Schedule and Share URL Filtering Reports (Strata Cloud Manager)
Whether you're using Panorama or Strata Cloud Manager to manage Prisma Access, you can use
Strata Cloud Manager for URL Filtering reports. In Strata Cloud Manager, go to
Activity for interactive URL Filtering data and reports. You can share Activity
reports within your organization and also schedule them for regular updates. Here
are the Prisma Access dashboards and tools that leverage and are most relevant
to URL Filtering:
- Executive Summary —See which URL categories account for the most web activity in your network, the top 10 malicious URLs, and top 10 high-risk URLs.
- User Activity —See individual users’ browsing patterns: their most frequently visited sites, the sites with which they’re transferring data, and attempts to access high-risk sites. The data from your URL Filtering logs and the Cloud Identity Engine enable this visibility.
- Search for a security artifact (an IP address, domain, URL, or file hash) to interact with data just for that artifact, drawn from both your network and global threat intelligence findings.
To
access user activity data and share reports easily and securely,
we recommend activating and configuring the Cloud Identity
Engine.
- Download, share, and schedule Activity reports.Access the URL filtering executive summary.Select ActivityExecutive Summary and click the URL Filtering tab.
Schedule and Share URL Filtering Reports (PAN-OS & Panorama)
- Add a new custom report.
- Select MonitorManage Custom Reports and Add a report.Give the report a unique Name, and optionally a Description.Select the Database you want to use to generate the report. To generate a detailed URL Filtering report, select URL from the Detailed Logs section:Configure report options.
- Select a predefined Time Frame or select Custom.Select the log columns to include in the report from the Available Columns list add them (
- Action
- App Category
- Category
- Destination Country
- Source User
- URL
If the firewall is enabled to prevent credential phishing, select the Attribute Flags, the Operator has and the Value Credential Detected to also include events in the report that record when a user submitted a valid corporate credential to a site.( Optional) Select a Sort By option to set the attribute to use to aggregate the report details. If you do not select an attribute to sort by, the report will return the first N number of results without any aggregation. Select a Group By attribute to use as an anchor for grouping data. The following example shows a report with Group By set to App Category and Sort By set to a Count of Top 5.Run the report.- Click the Run Now icon to immediately generate the report, which opens in a new tab.When you are done reviewing the report, go back to the Report Setting tab and either tune the settings and run the report again, or continue to the next step to schedule the report.Select the Schedule check box to run the report once per day. This will generate a daily report that details web activity over the last 24 hours.Commit the configuration.View the custom report.
- Select MonitorReports.Expand the Custom Reports pane in the right column and select the report you want to view. The latest report displays automatically.To view the report for a previous date, select the date from the calendar. You can also export the report to PDF, CSV, or XML.