- Products
- Learn
- Local User Groups
- Partners
- More
Access Control and Threat Prevention Best Practices
5 November @ 5pm CET / 11am ET
Ask Check Point Threat Intelligence Anything!
October 28th, 9am ET / 3pm CET
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
Spark Management Portal and More!
Hi Mates,
something that bugs me a long time.
We use manual created Application/Site-Objects with match by URL List.
Mostly the logs only show now the Application/Site-Object Name instead of one of the matching URLs.
So, Rules match because specific URLs are used ✅.
Search the log for this specific URL - no hits ❌.
Search the log for the IP of this specific URL -> shows hits but with the App-Name 💔.
Best would be to show the matched URL and in WHICH Application/Site-Object (if there is any).
Can we change this behavior or is this an RFE?
Cheers,
Dave
Btw, example I gave is from my lab, I just checked one of the logs for "ask" user check rule I created for ssl inspection.
Andy
Yes.
I sometimes see logs look like this as well. Cannot find one now 😅
In your screenshot you marked the app-name. It shows the URL. I assume there is no object with that URL.
On the right side of your LOG there is a Web Traffic Section. With the URL. That's what I expect.
The various ways of the logs look a like also bugs me 😉 Sometimes one section field is on the lefty sometimes on the righty...
Even if I do search appi_name:tsn.ca, I get exact same thing. This is R81.20 jumbo 96 lab.
Andy
I cant see any images, sorry. I cant sadly input any "embedded" images any more myself, as it gives me an error I reached 1000 images upload, so has to be attached 🙂
Andy
I forgot to add it in the post. But now also added it as attachement too 😁
I see it now 🙂
Not sure what to say, sorry. I checked every log regarding this in my lab in the last 6 months and they all show exactly what I sent you.
Dont know if it might be worth doing below sk...
Andy
https://support.checkpoint.com/results/sk/sk64280
hmmm no will not do that yet.
But thanks for breaking your head with me 😀
K, fair enough...I just had that sk in my notes, but maybe not needed here. I would open TAC case if I were you just to double check everything. If you need me to test anything in my lab, let me know.
Andy
Have you tried setting Extended Logging on the rule matching the custom site object? Be warned however that this will log every URL pulled by the browser, and should most definitely NOT be used on generic Internet surfing rules for hundreds or thousands of Internet surfing workstations.
Good idea.
Log was set to "Log"+Accounting.
To not kill the system I tried it now  with Detailed Log + Accounting. I do not think that change a lot at all. Log Details look the same. Already had details like browsing time and in/out packets/bytes etc.
Will have to create  a test rule for this case and the set it to extended log. Will report again when did this.
For what its worth, I also tested with extended logging option and logs look exactly the same, but let us know if test rule shows you anything different.
Andy
The only way to get the URLs accessed is via Extended Logging on the relevant rule(s).
So we have the full picture...
Do you currently inspect HTTPS traffic, how is QUIC handled?
Note sk131712 & sk178845 are typically relevant here.
 
					
				
				
			
		
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count | 
|---|---|
| 22 | |
| 16 | |
| 7 | |
| 6 | |
| 4 | |
| 4 | |
| 3 | |
| 3 | |
| 2 | |
| 2 | 
Tue 28 Oct 2025 @ 11:00 AM (EDT)
Under the Hood: CloudGuard Network Security for Google Cloud Network Security Integration - OverviewTue 28 Oct 2025 @ 12:30 PM (EDT)
Check Point & AWS Virtual Immersion Day: Web App ProtectionTue 28 Oct 2025 @ 11:00 AM (EDT)
Under the Hood: CloudGuard Network Security for Google Cloud Network Security Integration - OverviewTue 28 Oct 2025 @ 12:30 PM (EDT)
Check Point & AWS Virtual Immersion Day: Web App ProtectionThu 30 Oct 2025 @ 03:00 PM (CET)
Cloud Security Under Siege: Critical Insights from the 2025 Security Landscape - EMEAThu 30 Oct 2025 @ 11:00 AM (EDT)
Tips and Tricks 2025 #15: Become a Threat Exposure Management Power User!About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY