Question
how find out what URL is blocked by malicious URL filter
hello guys
i find out that 60% of firewall blocking traffic belongs to IPS rule malicious-URL. i forftigate monitoring section i could not find which user request with malicious URL are blocked. i configure a syslog server (Splunk) to gather firewall log, but still could not find the URL that caused IPS take an action to user request.
is any syslog configuration that could send User URL to syslog server ?
thanks
