Palo Alto Networks recommends setting
the real-time-detection action setting to alert for your active
URL filtering profiles. This provides visibility into URLs analyzed in
real-time and will block (or allow, depending on your policy settings)
based on the category settings configured for specific web threats.
The
firewall enforces the most severe action of the actions configured
for detected URL categories of a given URL. For example, suppose
example.com is categorized as real-time-detection, command-and-control,
and shopping—categories with an alert, block, and allow action configured,
respectively. The firewall will block the URL because block is the most
severe action from the detected categories.