<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HTTPS Inspection logs and App Control with URL Filtering in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-logs-and-App-Control-with-URL-Filtering/m-p/247300#M48286</link>
    <description>&lt;P&gt;I totally see the point&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3630"&gt;@Chris_Atkinson&lt;/a&gt;&amp;nbsp;made here. The way logging options are configured may have something to do with it.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Fri, 25 Apr 2025 10:45:18 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2025-04-25T10:45:18Z</dc:date>
    <item>
      <title>HTTPS Inspection logs and App Control with URL Filtering</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-logs-and-App-Control-with-URL-Filtering/m-p/247256#M48270</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;I'm a bit confused about the logs' reflection on URL filtering in the Check Point NGFW.&lt;/P&gt;&lt;P&gt;For example, I configured HTTPS inspection and App and URL filtering on the device.&lt;BR /&gt;go to YouTube and then see the logs about visiting youtube.com.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="App-inspect.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30317i2FA2EFAF27FAFAC7/image-size/large?v=v2&amp;amp;px=999" role="button" title="App-inspect.png" alt="App-inspect.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;but I see just some general information in the application logs and URL filtering logs&lt;BR /&gt;In HTTPS inspection logs, I can see information about the video resource that I watched.&lt;/P&gt;&lt;DIV class=""&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="HHTPS-inspect.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30318iF90AB424FA53E490/image-size/large?v=v2&amp;amp;px=999" role="button" title="HHTPS-inspect.png" alt="HHTPS-inspect.png" /&gt;&lt;/span&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why don't I see it on the application or URL filtering logs?&lt;/P&gt;&lt;P&gt;I mean the information about visiting&amp;nbsp;rr4---sn-5hne6nsk.googlevideo.com.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Apr 2025 16:12:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-logs-and-App-Control-with-URL-Filtering/m-p/247256#M48270</guid>
      <dc:creator>YvheniiK</dc:creator>
      <dc:date>2025-04-24T16:12:56Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection logs and App Control with URL Filtering</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-logs-and-App-Control-with-URL-Filtering/m-p/247267#M48275</link>
      <description>&lt;P&gt;Both URL filtering and https inspections have different values that are in a log entry. I posted them below. It could that there is a difference between them. You could open the full log entry and compare them with the table below. In case of the youtube.com log entry I suspect it just uses the info from the certificate itself *.google.com has also youtube.com in it.&amp;nbsp;&lt;/P&gt;
&lt;TABLE id="Unique_ID1Table" class="footnote" border="1" cellspacing="2" cellpadding="4"&gt;
&lt;TBODY&gt;
&lt;TR class="SubTitle" bgcolor="#ebebeb"&gt;
&lt;TD&gt;Field Name&lt;/TD&gt;
&lt;TD&gt;Field Display Name&lt;/TD&gt;
&lt;TD&gt;Type&lt;/TD&gt;
&lt;TD&gt;Description&lt;/TD&gt;
&lt;TD&gt;Indexed&lt;/TD&gt;
&lt;TD&gt;Added in Version&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;TABLE id="Unique_ID1Table" class="footnote" border="1" cellspacing="2" cellpadding="4"&gt;
&lt;TBODY&gt;
&lt;TR class="SubTitle" bgcolor="#ebebeb"&gt;
&lt;TD colspan="6"&gt;&lt;STRONG&gt;Security Gateway - HTTPS Inspection Fields - R81.20 and lower&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;https_inspection_action&lt;/TD&gt;
&lt;TD&gt;Inspection Action&lt;/TD&gt;
&lt;TD&gt;string&lt;/TD&gt;
&lt;TD&gt;HTTPS Inspection action (Inspect/Bypass/Error)&lt;/TD&gt;
&lt;TD&gt;Yes&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;https_inspection_rule_id&lt;/TD&gt;
&lt;TD&gt;HTTPS Inspection Rule ID&lt;/TD&gt;
&lt;TD&gt;string&lt;/TD&gt;
&lt;TD&gt;ID of the matched rule&lt;/TD&gt;
&lt;TD&gt;Yes&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;https_inspection_rule_name&lt;/TD&gt;
&lt;TD&gt;HTTPS Inspection Rule Name&lt;/TD&gt;
&lt;TD&gt;string&lt;/TD&gt;
&lt;TD&gt;Name of the matched rule&lt;/TD&gt;
&lt;TD&gt;Yes&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;app_properties&lt;/TD&gt;
&lt;TD&gt;Additional Categories&lt;/TD&gt;
&lt;TD&gt;string&lt;/TD&gt;
&lt;TD&gt;List of all found categories (match table)&lt;/TD&gt;
&lt;TD&gt;No&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;resource&lt;/TD&gt;
&lt;TD&gt;Resource&lt;/TD&gt;
&lt;TD&gt;string&lt;/TD&gt;
&lt;TD&gt;HTTPS resource&lt;BR /&gt;Possible values:&lt;BR /&gt;
&lt;UL&gt;
&lt;LI&gt;SNI&lt;/LI&gt;
&lt;LI&gt;Domain Name&lt;/LI&gt;
&lt;/UL&gt;
&lt;/TD&gt;
&lt;TD&gt;Yes&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;https_validation&lt;/TD&gt;
&lt;TD&gt;HTTPS Validation&lt;/TD&gt;
&lt;TD&gt;string&lt;/TD&gt;
&lt;TD&gt;Precise error, describing the HTTPS inspection failure&lt;/TD&gt;
&lt;TD&gt;Yes&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;description&lt;/TD&gt;
&lt;TD&gt;Description&lt;/TD&gt;
&lt;TD&gt;string&lt;/TD&gt;
&lt;TD&gt;Additional information about the "https_validation" field&lt;/TD&gt;
&lt;TD&gt;Yes&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;reason&lt;/TD&gt;
&lt;TD&gt;Reason&lt;/TD&gt;
&lt;TD&gt;string&lt;/TD&gt;
&lt;TD&gt;Explains the action decision&lt;/TD&gt;
&lt;TD&gt;Yes&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE id="Unique_ID1Table" class="footnote" border="1" cellspacing="2" cellpadding="4"&gt;
&lt;TBODY&gt;
&lt;TR class="SubTitle" bgcolor="#ebebeb"&gt;
&lt;TD&gt;Field Name&lt;/TD&gt;
&lt;TD&gt;Field Display Name&lt;/TD&gt;
&lt;TD&gt;Type&lt;/TD&gt;
&lt;TD&gt;Description&lt;/TD&gt;
&lt;TD&gt;Indexed&lt;/TD&gt;
&lt;TD&gt;Added in Version&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;TABLE id="Unique_ID1Table" class="footnote" border="1" cellspacing="2" cellpadding="4"&gt;
&lt;TBODY&gt;
&lt;TR class="SubTitle" bgcolor="#ebebeb"&gt;
&lt;TD colspan="6"&gt;&lt;STRONG&gt;Security Gateway - Application Control &amp;amp; URL Filtering Fields&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;appi_name&lt;/TD&gt;
&lt;TD&gt;Application Name&lt;/TD&gt;
&lt;TD&gt;string&lt;/TD&gt;
&lt;TD&gt;Application name (match table)&lt;/TD&gt;
&lt;TD&gt;Yes&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;app_desc&lt;/TD&gt;
&lt;TD&gt;Application Description&lt;/TD&gt;
&lt;TD&gt;string&lt;/TD&gt;
&lt;TD&gt;Application description (match table)&lt;/TD&gt;
&lt;TD&gt;No&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;app_id&lt;/TD&gt;
&lt;TD&gt;Application ID&lt;/TD&gt;
&lt;TD&gt;int&lt;/TD&gt;
&lt;TD&gt;Application ID (match table)&lt;/TD&gt;
&lt;TD&gt;No&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;app_properties&lt;/TD&gt;
&lt;TD&gt;Additional Categories&lt;/TD&gt;
&lt;TD&gt;string&lt;/TD&gt;
&lt;TD&gt;Application categories (match table)&lt;/TD&gt;
&lt;TD&gt;Yes&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;app_risk&lt;/TD&gt;
&lt;TD&gt;Application Risk&lt;/TD&gt;
&lt;TD&gt;int&lt;/TD&gt;
&lt;TD&gt;Application risk (match table)&lt;BR /&gt;Possible values:&lt;BR /&gt;
&lt;UL&gt;
&lt;LI&gt;0 - Unknown&lt;/LI&gt;
&lt;LI&gt;1 - Very low&lt;/LI&gt;
&lt;LI&gt;2 - Low&lt;/LI&gt;
&lt;LI&gt;3 - Medium&lt;/LI&gt;
&lt;LI&gt;4 - High&lt;/LI&gt;
&lt;LI&gt;5 - Critical&lt;/LI&gt;
&lt;/UL&gt;
&lt;/TD&gt;
&lt;TD&gt;Yes&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;app_rule_id&lt;/TD&gt;
&lt;TD&gt;Application Rule ID&lt;/TD&gt;
&lt;TD&gt;string&lt;/TD&gt;
&lt;TD&gt;Rule number&lt;/TD&gt;
&lt;TD&gt;Yes&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;app_rule_name&lt;/TD&gt;
&lt;TD&gt;Application Rule Name&lt;/TD&gt;
&lt;TD&gt;string&lt;/TD&gt;
&lt;TD&gt;Rule name&lt;/TD&gt;
&lt;TD&gt;No&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;app_sig_id&lt;/TD&gt;
&lt;TD&gt;Application Signature ID&lt;/TD&gt;
&lt;TD&gt;string&lt;/TD&gt;
&lt;TD&gt;The signature ID, by which the application was detected (match table)&lt;/TD&gt;
&lt;TD&gt;Yes&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;categories&lt;/TD&gt;
&lt;TD&gt;Categories&lt;/TD&gt;
&lt;TD&gt;string&lt;/TD&gt;
&lt;TD&gt;Matched categories&lt;/TD&gt;
&lt;TD&gt;Yes&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;certificate_resource&lt;/TD&gt;
&lt;TD&gt;Resource&lt;/TD&gt;
&lt;TD&gt;string&lt;/TD&gt;
&lt;TD&gt;HTTPS resource Possible values:&lt;BR /&gt;
&lt;UL&gt;
&lt;LI&gt;SNI&lt;/LI&gt;
&lt;LI&gt;Domain Name (DN)&lt;/LI&gt;
&lt;/UL&gt;
&lt;/TD&gt;
&lt;TD&gt;Yes&lt;/TD&gt;
&lt;TD&gt;R80.40&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;certificate_validation&lt;/TD&gt;
&lt;TD&gt;Certificate Validation&lt;/TD&gt;
&lt;TD&gt;string&lt;/TD&gt;
&lt;TD&gt;Precise error, describing HTTPS certificate failure under "HTTPS categorize websites" feature&lt;/TD&gt;
&lt;TD&gt;Yes&lt;/TD&gt;
&lt;TD&gt;R80.40&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;description&lt;/TD&gt;
&lt;TD&gt;Description&lt;/TD&gt;
&lt;TD&gt;string&lt;/TD&gt;
&lt;TD&gt;Additional explanation about the certificate validation failure&lt;/TD&gt;
&lt;TD&gt;Yes&lt;/TD&gt;
&lt;TD&gt;R80.40&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;usercheck_incident_uid&lt;/TD&gt;
&lt;TD&gt;UserCheck ID&lt;/TD&gt;
&lt;TD&gt;string&lt;/TD&gt;
&lt;TD&gt;UserCheck incident ID&lt;/TD&gt;
&lt;TD&gt;No&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;usercheck_reference&lt;/TD&gt;
&lt;TD&gt;UserCheck Reference&lt;/TD&gt;
&lt;TD&gt;string&lt;/TD&gt;
&lt;TD&gt;UserCheck reference&lt;/TD&gt;
&lt;TD&gt;No&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;resource&lt;/TD&gt;
&lt;TD&gt;Resource&lt;/TD&gt;
&lt;TD&gt;string&lt;/TD&gt;
&lt;TD&gt;HTTP connection resource&lt;/TD&gt;
&lt;TD&gt;Yes&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;browse_time&lt;/TD&gt;
&lt;TD&gt;Browse Time&lt;/TD&gt;
&lt;TD&gt;time&lt;/TD&gt;
&lt;TD&gt;Application session browse time&lt;/TD&gt;
&lt;TD&gt;Yes&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;limit_requested&lt;/TD&gt;
&lt;TD&gt;N/A&lt;/TD&gt;
&lt;TD&gt;int&lt;/TD&gt;
&lt;TD&gt;Indicates whether data limit was requested for the session&lt;/TD&gt;
&lt;TD&gt;Yes&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;limit_applied&lt;/TD&gt;
&lt;TD&gt;N/A&lt;/TD&gt;
&lt;TD&gt;int&lt;/TD&gt;
&lt;TD&gt;Indicates whether the session was actually date-limited&lt;/TD&gt;
&lt;TD&gt;Yes&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;dropped_outgoing&lt;/TD&gt;
&lt;TD&gt;N/A&lt;/TD&gt;
&lt;TD&gt;int&lt;/TD&gt;
&lt;TD&gt;Number&amp;nbsp;of outgoing dropped packets&lt;/TD&gt;
&lt;TD&gt;Yes&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;dropped_incoming&lt;/TD&gt;
&lt;TD&gt;N/A&lt;/TD&gt;
&lt;TD&gt;int&lt;/TD&gt;
&lt;TD&gt;Number&amp;nbsp;of incoming dropped packets&lt;/TD&gt;
&lt;TD&gt;Yes&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;dropped_total&lt;/TD&gt;
&lt;TD&gt;N/A&lt;/TD&gt;
&lt;TD&gt;int&lt;/TD&gt;
&lt;TD&gt;Number&amp;nbsp;of dropped packets (both incoming and outgoing)&lt;/TD&gt;
&lt;TD&gt;Yes&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;suppressed_logs&lt;/TD&gt;
&lt;TD&gt;Suppressed Logs&lt;/TD&gt;
&lt;TD&gt;int&lt;/TD&gt;
&lt;TD&gt;Number of connections/HTTP sessions that were aggregated in this application session log&lt;/TD&gt;
&lt;TD&gt;No&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;match_id&lt;/TD&gt;
&lt;TD&gt;N/A&lt;/TD&gt;
&lt;TD&gt;int&lt;/TD&gt;
&lt;TD&gt;Mapping of matched rule to its matched application (match table)&lt;/TD&gt;
&lt;TD&gt;Yes&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;client_type_os&lt;/TD&gt;
&lt;TD&gt;N/A&lt;/TD&gt;
&lt;TD&gt;string&lt;/TD&gt;
&lt;TD&gt;Client OS detected in the HTTP request&lt;/TD&gt;
&lt;TD&gt;Yes&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;referrer&lt;/TD&gt;
&lt;TD&gt;N/A&lt;/TD&gt;
&lt;TD&gt;string&lt;/TD&gt;
&lt;TD&gt;The referrer header, if exists&lt;/TD&gt;
&lt;TD&gt;Yes&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;name&lt;/TD&gt;
&lt;TD&gt;N/A&lt;/TD&gt;
&lt;TD&gt;string&lt;/TD&gt;
&lt;TD&gt;Application name&lt;/TD&gt;
&lt;TD&gt;Yes&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;properties&lt;/TD&gt;
&lt;TD&gt;N/A&lt;/TD&gt;
&lt;TD&gt;string&lt;/TD&gt;
&lt;TD&gt;Application categories (match table)&lt;/TD&gt;
&lt;TD&gt;Yes&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;risk&lt;/TD&gt;
&lt;TD&gt;N/A&lt;/TD&gt;
&lt;TD&gt;int&lt;/TD&gt;
&lt;TD&gt;Application risk&lt;/TD&gt;
&lt;TD&gt;Yes&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;sig_id&lt;/TD&gt;
&lt;TD&gt;N/A&lt;/TD&gt;
&lt;TD&gt;string&lt;/TD&gt;
&lt;TD&gt;Application's signature ID, by which it was detected&lt;/TD&gt;
&lt;TD&gt;Yes&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;desc&lt;/TD&gt;
&lt;TD&gt;N/A&lt;/TD&gt;
&lt;TD&gt;string&lt;/TD&gt;
&lt;TD&gt;Override application description&lt;/TD&gt;
&lt;TD&gt;Yes&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;referrer_self_uid&lt;/TD&gt;
&lt;TD&gt;N/A&lt;/TD&gt;
&lt;TD&gt;guid&lt;/TD&gt;
&lt;TD&gt;UUID of the current log&lt;/TD&gt;
&lt;TD&gt;Yes&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;referrer_parent_uid&lt;/TD&gt;
&lt;TD&gt;N/A&lt;/TD&gt;
&lt;TD&gt;guid&lt;/TD&gt;
&lt;TD&gt;Log UUID of the referring application&lt;/TD&gt;
&lt;TD&gt;Yes&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;needs_browse_time&lt;/TD&gt;
&lt;TD&gt;N/A&lt;/TD&gt;
&lt;TD&gt;int&lt;/TD&gt;
&lt;TD&gt;Browse time required for the connection&lt;/TD&gt;
&lt;TD&gt;Yes&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;security_inzone&lt;/TD&gt;
&lt;TD&gt;N/A&lt;/TD&gt;
&lt;TD&gt;string&lt;/TD&gt;
&lt;TD&gt;Source security zone&lt;/TD&gt;
&lt;TD&gt;Yes&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;security_outzone&lt;/TD&gt;
&lt;TD&gt;N/A&lt;/TD&gt;
&lt;TD&gt;string&lt;/TD&gt;
&lt;TD&gt;Destination security zone&lt;/TD&gt;
&lt;TD&gt;Yes&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;url&lt;/TD&gt;
&lt;TD&gt;URL&lt;/TD&gt;
&lt;TD&gt;string&lt;/TD&gt;
&lt;TD&gt;Matched URL&lt;/TD&gt;
&lt;TD&gt;Yes&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;app_byte_ps_in&lt;/TD&gt;
&lt;TD&gt;Application Byte/Sec In&lt;/TD&gt;
&lt;TD&gt;int&lt;/TD&gt;
&lt;TD&gt;Incoming traffic of an application (Bytes per Second)&lt;/TD&gt;
&lt;TD&gt;No&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;app_byte_ps_out&lt;/TD&gt;
&lt;TD&gt;Application Byte/Sec Out/td&amp;gt;&lt;/TD&gt;
&lt;TD&gt;int&lt;/TD&gt;
&lt;TD&gt;Outgoing traffic of an application (Bytes per Second)&lt;/TD&gt;
&lt;TD&gt;No&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;app_pack_ps_in&lt;/TD&gt;
&lt;TD&gt;Application Packet/Sec In&lt;/TD&gt;
&lt;TD&gt;int&lt;/TD&gt;
&lt;TD&gt;Incoming traffic of an application (Packets per Second)&lt;/TD&gt;
&lt;TD&gt;No&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;app_pack_ps_out&lt;/TD&gt;
&lt;TD&gt;Application Packet/Sec Out/td&amp;gt;&lt;/TD&gt;
&lt;TD&gt;int&lt;/TD&gt;
&lt;TD&gt;Outgoing traffic of an application (Packets per Second)&lt;/TD&gt;
&lt;TD&gt;No&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;matched_application&lt;/TD&gt;
&lt;TD&gt;Matched Application&lt;/TD&gt;
&lt;TD&gt;string&lt;/TD&gt;
&lt;TD&gt;Name of the matched application&lt;/TD&gt;
&lt;TD&gt;No&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;</description>
      <pubDate>Thu, 24 Apr 2025 20:36:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-logs-and-App-Control-with-URL-Filtering/m-p/247267#M48275</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2025-04-24T20:36:53Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection logs and App Control with URL Filtering</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-logs-and-App-Control-with-URL-Filtering/m-p/247268#M48276</link>
      <description>&lt;P&gt;I believe thats normal. I also see the same in my R82 lab as well.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 24 Apr 2025 23:07:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-logs-and-App-Control-with-URL-Filtering/m-p/247268#M48276</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-24T23:07:42Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection logs and App Control with URL Filtering</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-logs-and-App-Control-with-URL-Filtering/m-p/247269#M48277</link>
      <description>&lt;P&gt;Which level of logging is configured for the matching rule in the track column, remember there are additional options here i.e. Extended and Detailed.&lt;/P&gt;
&lt;P&gt;Session vs connection logs may also be a factor...&lt;/P&gt;</description>
      <pubDate>Fri, 25 Apr 2025 00:11:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-logs-and-App-Control-with-URL-Filtering/m-p/247269#M48277</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2025-04-25T00:11:27Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection logs and App Control with URL Filtering</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-logs-and-App-Control-with-URL-Filtering/m-p/247296#M48282</link>
      <description>&lt;P&gt;That is clear to me, and I know that HTTPS-inspection and Application Control &amp;amp; URL Filtering loglines have different fields.&lt;BR /&gt;My question here is more about a count of these loglines.&lt;BR /&gt;When I have a YouTube session, I see that I have many more loglines in HTTPS-inspection than in Application Control &amp;amp; URL Filtering.&lt;BR /&gt;I have just 1 logline in Application Control &amp;amp; URL Filtering about youtube session, but 4-6 loglines (where specified various resources and dst IP) in HTTPS-inspection in the scope of this youtube session.&lt;BR /&gt;That means that if I want to get full information about web-filtering, then I need to pay attention to both logs "HTTPS-inspection" and "Application Control &amp;amp; URL Filtering".&lt;BR /&gt;And the worst thing here is that you can't correlate these two types of logs (by sessionid,loguid or somewhere else)&lt;/P&gt;</description>
      <pubDate>Fri, 25 Apr 2025 09:48:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-logs-and-App-Control-with-URL-Filtering/m-p/247296#M48282</guid>
      <dc:creator>YvheniiK</dc:creator>
      <dc:date>2025-04-25T09:48:01Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection logs and App Control with URL Filtering</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-logs-and-App-Control-with-URL-Filtering/m-p/247297#M48283</link>
      <description>&lt;P&gt;You have not indicated how the logging/track field is currently configured for your related policy/rules?&lt;/P&gt;</description>
      <pubDate>Fri, 25 Apr 2025 09:53:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-logs-and-App-Control-with-URL-Filtering/m-p/247297#M48283</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2025-04-25T09:53:00Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection logs and App Control with URL Filtering</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-logs-and-App-Control-with-URL-Filtering/m-p/247300#M48286</link>
      <description>&lt;P&gt;I totally see the point&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3630"&gt;@Chris_Atkinson&lt;/a&gt;&amp;nbsp;made here. The way logging options are configured may have something to do with it.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 25 Apr 2025 10:45:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-logs-and-App-Control-with-URL-Filtering/m-p/247300#M48286</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-25T10:45:18Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection logs and App Control with URL Filtering</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-logs-and-App-Control-with-URL-Filtering/m-p/247341#M48302</link>
      <description>&lt;P&gt;I configured it&amp;nbsp;like this&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Policy.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30326iBAD0392648CE1054/image-size/large?v=v2&amp;amp;px=999" role="button" title="Policy.png" alt="Policy.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="track.png" style="width: 303px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30328i68D8AA91E8FF0F3B/image-size/large?v=v2&amp;amp;px=999" role="button" title="track.png" alt="track.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Also&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Logs-sett.png" style="width: 582px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30327i304CCA162B464740/image-size/large?v=v2&amp;amp;px=999" role="button" title="Logs-sett.png" alt="Logs-sett.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Apr 2025 14:38:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-logs-and-App-Control-with-URL-Filtering/m-p/247341#M48302</guid>
      <dc:creator>YvheniiK</dc:creator>
      <dc:date>2025-04-25T14:38:40Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection logs and App Control with URL Filtering</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-logs-and-App-Control-with-URL-Filtering/m-p/247360#M48306</link>
      <description>&lt;P&gt;Oh sorry,&amp;nbsp;&lt;/P&gt;&lt;P&gt;enabling extended log solves this problem.&lt;BR /&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Fri, 25 Apr 2025 16:35:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-logs-and-App-Control-with-URL-Filtering/m-p/247360#M48306</guid>
      <dc:creator>YvheniiK</dc:creator>
      <dc:date>2025-04-25T16:35:29Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection logs and App Control with URL Filtering</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-logs-and-App-Control-with-URL-Filtering/m-p/247361#M48307</link>
      <description>&lt;P&gt;Good job&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/103230"&gt;@YvheniiK&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Apr 2025 16:36:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-logs-and-App-Control-with-URL-Filtering/m-p/247361#M48307</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-25T16:36:52Z</dc:date>
    </item>
  </channel>
</rss>

