HTTP Header Logging
Focus
Focus
Next-Generation Firewall

HTTP Header Logging

Table of Contents

HTTP Header Logging

Select ObjectsSecurity ProfilesURL FilteringHTTP Header Logging to configure which HTTP headers to capture in URL filtering logs.
HTTP headers can only be logged when traffic is decrypted. Ensure a decryption policy is in place for the traffic you want to inspect.
  • Log all HTTP headers—Captures every request and response header.
  • Request Headers—Add specific request headers to capture. Each entry has a per-header Max Header Length and Truncate Headers override. Request headers can contain personally identifiable information (PII) such as cookies and authorization tokens; a privacy notice appears when you first enable request header logging.
  • Response Headers—Add specific response headers to capture. Each entry has a per-header Max Header Length and Truncate Headers override.
  • Enable logging of response code in HTTP response—The HTTP response status code is captured in every response log entry. When response header logging is disabled or no response headers are matched, enabling this option forces a response log entry to capture the status code.
  • Max Header Length—Maximum bytes to capture per header value (1–4,092). The limit applies to the header value only, excluding the header name, colon, and whitespace. Individual headers in the Request Headers or Response Headers tables can override this value. If set to 1 with Enable truncation of headers that exceed the max header length limit enabled, only the header name is logged.
  • Enable truncation of headers that exceed the max header length limit—When enabled, captures headers up to the Max Header Length limit. When disabled, headers that exceed the limit are not logged.
When you log both request and response headers, the firewall generates two URL filtering log entries per resource. Use the URL Index and Direction fields to correlate the entries.