<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Extended logging info in log export in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Extended-logging-info-in-log-export/m-p/273761#M104229</link>
    <description>&lt;P&gt;If you don't mind getting your hands dirty, maybe you can pull the information from the API:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/latest/APIs/index.html#cli/show-logs~v2.1%20" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/latest/APIs/index.html#cli/show-logs~v2.1%20&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 18 Mar 2026 22:24:50 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2026-03-18T22:24:50Z</dc:date>
    <item>
      <title>Extended logging info in log export</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Extended-logging-info-in-log-export/m-p/273601#M104154</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;We have Extended Logging enabled on a particular rule in our firewall. We want to extract URLS from traffic that matches that rule and make the decision to add them to our allowlist or not. However, when I export logs to CSV with our rule and timeframe of interest, the URLs that are shown in the "Session &amp;gt; Web Traffic &amp;gt; Resource (see pic below)" subsection of the connection are not shown in the log file, even with all columns enabled. I was unable to find anything to have this information to show up in that log (or any other log), even though I have tried every logical search term that I can think of. Is there a setting that we're missing? Is there another way to get this information in a nice, orderly manner, perhaps with the Log Exporter? I am happy to read the documentation necessary, but right now I just cannot find _what_ I need exactly. Hope you guys are willing to point me in the right direction &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;AB&lt;/P&gt;&lt;P&gt;1900/2000 appliance, version R81.10, cannot find information on which take is installed. Application Control &amp;amp; URL Filtering blades are enabled.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Mar 2026 15:42:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Extended-logging-info-in-log-export/m-p/273601#M104154</guid>
      <dc:creator>AB136785</dc:creator>
      <dc:date>2026-03-17T15:42:52Z</dc:date>
    </item>
    <item>
      <title>Re: Extended logging info in log export</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Extended-logging-info-in-log-export/m-p/273611#M104161</link>
      <description>&lt;P&gt;is it possible to share&amp;nbsp;&lt;SPAN&gt;$EXPORTERDIR/targets/&amp;lt;&lt;/SPAN&gt;&lt;EM&gt;Name of&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_lx variable"&gt;Log Exporter&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Configuration&lt;/EM&gt;&lt;SPAN&gt;&amp;gt;/conf/FilterConfiguration.xml ?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Mar 2026 16:22:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Extended-logging-info-in-log-export/m-p/273611#M104161</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2026-03-17T16:22:09Z</dc:date>
    </item>
    <item>
      <title>Re: Extended logging info in log export</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Extended-logging-info-in-log-export/m-p/273655#M104182</link>
      <description>&lt;P&gt;Original poster was exporting logs from SmartView, which likely does not contain all the log fields.&lt;BR /&gt;Changing that would likely require an RFE.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Log Exporter is for sending logs to a SIEM, which is probably not what you're looking for here.&lt;BR /&gt;I believe SmartEvent can provide this information (with the right report).&lt;/P&gt;</description>
      <pubDate>Wed, 18 Mar 2026 00:02:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Extended-logging-info-in-log-export/m-p/273655#M104182</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-03-18T00:02:10Z</dc:date>
    </item>
    <item>
      <title>Re: Extended logging info in log export</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Extended-logging-info-in-log-export/m-p/273682#M104193</link>
      <description>&lt;P&gt;Thank you both for the replies so far. Indeed, I was exporting logs using the Web Smartconsole, apologies for not clarifying that initially. All I'm looking for is a table/list of URLs that were visited in a specified timeframe by specific hosts, preferrably with an easier method than manually going through the logs, clicking on the events of interest, and looking at the session info manually for every event I need. Since you're suggesting filing a Request for Enhancement, I take it that that functionality does not exist (yet).&lt;/P&gt;&lt;P&gt;I'll create the RFE. In the meantime, if anyone else has some suggestions to achieve this - or another method to specifically filter specific destinations and downloads - feel free to contribute.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Mar 2026 10:35:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Extended-logging-info-in-log-export/m-p/273682#M104193</guid>
      <dc:creator>AB136785</dc:creator>
      <dc:date>2026-03-18T10:35:21Z</dc:date>
    </item>
    <item>
      <title>Re: Extended logging info in log export</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Extended-logging-info-in-log-export/m-p/273761#M104229</link>
      <description>&lt;P&gt;If you don't mind getting your hands dirty, maybe you can pull the information from the API:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/latest/APIs/index.html#cli/show-logs~v2.1%20" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/latest/APIs/index.html#cli/show-logs~v2.1%20&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Mar 2026 22:24:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Extended-logging-info-in-log-export/m-p/273761#M104229</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-03-18T22:24:50Z</dc:date>
    </item>
    <item>
      <title>Re: Extended logging info in log export</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Extended-logging-info-in-log-export/m-p/273838#M104257</link>
      <description>&lt;P&gt;Ah my mistake was thinking this was about log exporter&lt;/P&gt;</description>
      <pubDate>Thu, 19 Mar 2026 17:35:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Extended-logging-info-in-log-export/m-p/273838#M104257</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2026-03-19T17:35:45Z</dc:date>
    </item>
  </channel>
</rss>

