<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA url logging in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-url-logging/m-p/1321544#M417658</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Panos,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;here is what I get when I browse to &lt;A class="jive-link-custom" href="http://www.microsoft.com" target="_blank"&gt;http://www.microsoft.com&lt;/A&gt; - no sign of &lt;A class="jive-link-custom" href="http://www.microsoft.com" target="_blank"&gt;www.microsoft.com&lt;/A&gt; here, I'm afraid.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa# Nov 17 2009 16:16:23: %ASA-5-304001: 30.30.30.30 Accessed URL 207.46.1&lt;/P&gt;&lt;P&gt;9.190:/&lt;/P&gt;&lt;P&gt;Nov 17 2009 16:16:24: %ASA-5-304001: 30.30.30.30 Accessed URL 207.46.19.190:/en/&lt;/P&gt;&lt;P&gt;shared/core/2/js/js.ashx?s=Csp;shared&lt;/P&gt;&lt;P&gt;Nov 17 2009 16:16:24: %ASA-5-304001: 30.30.30.30 Accessed URL 207.46.19.190:/en/&lt;/P&gt;&lt;P&gt;shared/core/2/css/css.ashx?sc=/en/us/site.config&amp;amp;pc=/En/us/PageConfig/win7/Direc&lt;/P&gt;&lt;P&gt;tInstall.config.xml&amp;amp;m=cspMscomHomePageBase&amp;amp;ie=true&lt;/P&gt;&lt;P&gt;Nov 17 2009 16:16:25: %ASA-5-304001: 30.30.30.30 Accessed URL 207.46.19.190:/en/&lt;/P&gt;&lt;P&gt;shared/core/2/css/css.ashx?sc=/en/us/site.config&amp;amp;pc=/En/us/PageConfig/win7/Direc&lt;/P&gt;&lt;P&gt;tInstall.config.xml&amp;amp;c=cspMscomHeader&amp;amp;ie=true&lt;/P&gt;&lt;P&gt;Nov 17 2009 16:16:26: %ASA-5-304001: 30.30.30.30 Accessed URL 92.122.189.48:/lib&lt;/P&gt;&lt;P&gt;rary/svy/broker.js&lt;/P&gt;&lt;P&gt;Nov 17 2009 16:16:27: %ASA-5-304001: 30.30.30.30 Accessed URL 207.46.19.190:/glo&lt;/P&gt;&lt;P&gt;bal/en/us/RenderingAssets/win7/TakeOverScript.js&lt;/P&gt;&lt;P&gt;Nov 17 2009 16:16:28: %ASA-5-304001: 30.30.30.30 Accessed URL 92.122.189.48:/glo&lt;/P&gt;&lt;P&gt;bal/En/PublishingImages/m.ms1.png&lt;/P&gt;&lt;P&gt;Nov 17 2009 16:16:28: %ASA-5-304001: 30.30.30.30 Accessed URL 92.122.189.48:/glo&lt;/P&gt;&lt;P&gt;bal/en/publishingimages/sitebrand/microsoft.gif&lt;/P&gt;&lt;P&gt;Nov 17 2009 16:16:28: %ASA-5-304001: 30.30.30.30 Accessed URL 207.46.19.190:/glo&lt;/P&gt;&lt;P&gt;bal/En/us/RenderingAssets/SLWindowPane/WindowPane_eventHandlers_111609.js&lt;/P&gt;&lt;P&gt;Nov 17 2009 16:16:29: %ASA-5-304001: 30.30.30.30 Accessed URL 213.199.141.139:/A&lt;/P&gt;&lt;P&gt;DSAdClient31.dll?GetSAd=&amp;amp;DPJS=4&amp;amp;PG=CMSNGN&amp;amp;AP=1087&lt;/P&gt;&lt;P&gt;Nov 17 2009 16:16:30: %ASA-5-304001: 30.30.30.30 Accessed URL 207.46.148.31:/MRT&lt;/P&gt;&lt;P&gt;/iview/173914879/direct/01?click=&lt;/P&gt;&lt;P&gt;Nov 17 2009 16:16:31: %ASA-5-304001: 30.30.30.30 Accessed URL 92.122.189.35:/lib&lt;/P&gt;&lt;P&gt;rary/svy/broker-config.js?1258474626906&lt;/P&gt;&lt;P&gt;Nov 17 2009 16:16:31: %ASA-5-304001: 30.30.30.30 Accessed URL 213.199.149.93:/b/&lt;/P&gt;&lt;P&gt;NMMRTSHARPCU/FY10_WinPhone_180x150_intrepid_v3_1022091609.gif&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 17 Nov 2009 16:19:52 GMT</pubDate>
    <dc:creator>scottwilliamson</dc:creator>
    <dc:date>2009-11-17T16:19:52Z</dc:date>
    <item>
      <title>ASA url logging</title>
      <link>https://community.cisco.com/t5/network-security/asa-url-logging/m-p/1321536#M417648</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm attempting to make our ASA log urls and I am getting some success. However, the output presents the IP instead of the actual domain, e.g, when browsing to imdb it is logged as:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nov 16 2009 14:12:35: %ASA-5-304001: 30.30.30.30 Accessed URL 209.85.229.148:/ad&lt;/P&gt;&lt;P&gt;j/imdb2.consumer.homepage/;tile=2;sz=468x60,728x90,1008x150,9x1;p=t;s=32;;ord=99&lt;/P&gt;&lt;P&gt;73051011677648&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rather than imdb.com/....(or whatever it happens to be).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How do I get the ASA to log the domain rather than the corresponding IP address?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/ps6128/products_configuration_example09186a0080ac2fda.shtml#related" target="_blank"&gt;http://www.cisco.com/en/US/products/ps6128/products_configuration_example09186a0080ac2fda.shtml#related&lt;/A&gt;&lt;/P&gt;&lt;P&gt;states the ASA has to run vers 8.0.4.24 or later, ours has  8.2(1).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 11:48:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-url-logging/m-p/1321536#M417648</guid>
      <dc:creator>scottwilliamson</dc:creator>
      <dc:date>2020-02-21T11:48:02Z</dc:date>
    </item>
    <item>
      <title>Re: ASA url logging</title>
      <link>https://community.cisco.com/t5/network-security/asa-url-logging/m-p/1321537#M417649</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Scott,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ASA will not log the url. There is an enhancement request for the syslog 304001 to log the url but it hasn't been fixed and I don't have an ETA for it as it is not in roadmap.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FYI, the enhancement request is CSCdt32288.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it makes it clear.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Nov 2009 18:43:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-url-logging/m-p/1321537#M417649</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2009-11-16T18:43:50Z</dc:date>
    </item>
    <item>
      <title>Re: ASA url logging</title>
      <link>https://community.cisco.com/t5/network-security/asa-url-logging/m-p/1321538#M417652</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Testing it here locally it seems there are changes that have been implemented.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When going to microsoft.com I saw log &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;%ASA-5-304001: 192.168.1.2 Accessed URL 207.46.19.190:&lt;A class="jive-link-custom" href="http://www.microsoft.com/" target="_blank"&gt;http://www.microsoft.com/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was doing just http inspection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;  ...&lt;/P&gt;&lt;P&gt;  inspect http&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;running ASA 8.2.1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Nov 2009 18:52:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-url-logging/m-p/1321538#M417652</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2009-11-16T18:52:23Z</dc:date>
    </item>
    <item>
      <title>Re: ASA url logging</title>
      <link>https://community.cisco.com/t5/network-security/asa-url-logging/m-p/1321539#M417653</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Panos,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So would the best summary of the situation be to say that the ASA does log the full url in a proportion of cases, dependant on how the website's url is put together, perhaps?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Nov 2009 09:10:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-url-logging/m-p/1321539#M417653</guid>
      <dc:creator>scottwilliamson</dc:creator>
      <dc:date>2009-11-17T09:10:01Z</dc:date>
    </item>
    <item>
      <title>Re: ASA url logging</title>
      <link>https://community.cisco.com/t5/network-security/asa-url-logging/m-p/1321540#M417654</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've tried browsing to &lt;A class="jive-link-custom" href="http://www.microsoft.com" target="_blank"&gt;www.microsoft.com&lt;/A&gt; and although I get different IP addresses (possibly as I'm in the UK) it doesn't resolve the url. Can you specify a dns server in the ASA somehow?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Nov 2009 09:21:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-url-logging/m-p/1321540#M417654</guid>
      <dc:creator>scottwilliamson</dc:creator>
      <dc:date>2009-11-17T09:21:39Z</dc:date>
    </item>
    <item>
      <title>Re: ASA url logging</title>
      <link>https://community.cisco.com/t5/network-security/asa-url-logging/m-p/1321541#M417655</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Scott,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That is correct. Note that even in your log you have "/adj/imdb2.consumer.homepage/" which is probably the uri of the GET request. So the URL in the get is logged.I believe you would have a log for the initial GET to imdb.com.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How about if you try microsoft as I did? You should see the same initial log there an then a bunch of other logs for the subsequent GETs done to complete the page.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Nov 2009 15:26:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-url-logging/m-p/1321541#M417655</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2009-11-17T15:26:20Z</dc:date>
    </item>
    <item>
      <title>Re: ASA url logging</title>
      <link>https://community.cisco.com/t5/network-security/asa-url-logging/m-p/1321542#M417656</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The DNS server on the ASA. It is the GEt that the ASA should be logging.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Nov 2009 15:28:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-url-logging/m-p/1321542#M417656</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2009-11-17T15:28:07Z</dc:date>
    </item>
    <item>
      <title>Re: ASA url logging</title>
      <link>https://community.cisco.com/t5/network-security/asa-url-logging/m-p/1321543#M417657</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Panos,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry, I don't underestand - could you explain this to me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Nov 2009 15:32:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-url-logging/m-p/1321543#M417657</guid>
      <dc:creator>scottwilliamson</dc:creator>
      <dc:date>2009-11-17T15:32:50Z</dc:date>
    </item>
    <item>
      <title>Re: ASA url logging</title>
      <link>https://community.cisco.com/t5/network-security/asa-url-logging/m-p/1321544#M417658</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Panos,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;here is what I get when I browse to &lt;A class="jive-link-custom" href="http://www.microsoft.com" target="_blank"&gt;http://www.microsoft.com&lt;/A&gt; - no sign of &lt;A class="jive-link-custom" href="http://www.microsoft.com" target="_blank"&gt;www.microsoft.com&lt;/A&gt; here, I'm afraid.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa# Nov 17 2009 16:16:23: %ASA-5-304001: 30.30.30.30 Accessed URL 207.46.1&lt;/P&gt;&lt;P&gt;9.190:/&lt;/P&gt;&lt;P&gt;Nov 17 2009 16:16:24: %ASA-5-304001: 30.30.30.30 Accessed URL 207.46.19.190:/en/&lt;/P&gt;&lt;P&gt;shared/core/2/js/js.ashx?s=Csp;shared&lt;/P&gt;&lt;P&gt;Nov 17 2009 16:16:24: %ASA-5-304001: 30.30.30.30 Accessed URL 207.46.19.190:/en/&lt;/P&gt;&lt;P&gt;shared/core/2/css/css.ashx?sc=/en/us/site.config&amp;amp;pc=/En/us/PageConfig/win7/Direc&lt;/P&gt;&lt;P&gt;tInstall.config.xml&amp;amp;m=cspMscomHomePageBase&amp;amp;ie=true&lt;/P&gt;&lt;P&gt;Nov 17 2009 16:16:25: %ASA-5-304001: 30.30.30.30 Accessed URL 207.46.19.190:/en/&lt;/P&gt;&lt;P&gt;shared/core/2/css/css.ashx?sc=/en/us/site.config&amp;amp;pc=/En/us/PageConfig/win7/Direc&lt;/P&gt;&lt;P&gt;tInstall.config.xml&amp;amp;c=cspMscomHeader&amp;amp;ie=true&lt;/P&gt;&lt;P&gt;Nov 17 2009 16:16:26: %ASA-5-304001: 30.30.30.30 Accessed URL 92.122.189.48:/lib&lt;/P&gt;&lt;P&gt;rary/svy/broker.js&lt;/P&gt;&lt;P&gt;Nov 17 2009 16:16:27: %ASA-5-304001: 30.30.30.30 Accessed URL 207.46.19.190:/glo&lt;/P&gt;&lt;P&gt;bal/en/us/RenderingAssets/win7/TakeOverScript.js&lt;/P&gt;&lt;P&gt;Nov 17 2009 16:16:28: %ASA-5-304001: 30.30.30.30 Accessed URL 92.122.189.48:/glo&lt;/P&gt;&lt;P&gt;bal/En/PublishingImages/m.ms1.png&lt;/P&gt;&lt;P&gt;Nov 17 2009 16:16:28: %ASA-5-304001: 30.30.30.30 Accessed URL 92.122.189.48:/glo&lt;/P&gt;&lt;P&gt;bal/en/publishingimages/sitebrand/microsoft.gif&lt;/P&gt;&lt;P&gt;Nov 17 2009 16:16:28: %ASA-5-304001: 30.30.30.30 Accessed URL 207.46.19.190:/glo&lt;/P&gt;&lt;P&gt;bal/En/us/RenderingAssets/SLWindowPane/WindowPane_eventHandlers_111609.js&lt;/P&gt;&lt;P&gt;Nov 17 2009 16:16:29: %ASA-5-304001: 30.30.30.30 Accessed URL 213.199.141.139:/A&lt;/P&gt;&lt;P&gt;DSAdClient31.dll?GetSAd=&amp;amp;DPJS=4&amp;amp;PG=CMSNGN&amp;amp;AP=1087&lt;/P&gt;&lt;P&gt;Nov 17 2009 16:16:30: %ASA-5-304001: 30.30.30.30 Accessed URL 207.46.148.31:/MRT&lt;/P&gt;&lt;P&gt;/iview/173914879/direct/01?click=&lt;/P&gt;&lt;P&gt;Nov 17 2009 16:16:31: %ASA-5-304001: 30.30.30.30 Accessed URL 92.122.189.35:/lib&lt;/P&gt;&lt;P&gt;rary/svy/broker-config.js?1258474626906&lt;/P&gt;&lt;P&gt;Nov 17 2009 16:16:31: %ASA-5-304001: 30.30.30.30 Accessed URL 213.199.149.93:/b/&lt;/P&gt;&lt;P&gt;NMMRTSHARPCU/FY10_WinPhone_180x150_intrepid_v3_1022091609.gif&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Nov 2009 16:19:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-url-logging/m-p/1321544#M417658</guid>
      <dc:creator>scottwilliamson</dc:creator>
      <dc:date>2009-11-17T16:19:52Z</dc:date>
    </item>
    <item>
      <title>Re: ASA url logging</title>
      <link>https://community.cisco.com/t5/network-security/asa-url-logging/m-p/1321545#M417659</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;From the logs posted, it appears the GET is being logged, but not the Host header. The Host header is the part of the request that would tell you which site at the logged IP address was accessed.It comes before the GET.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Name-based virtual hosts (in HTTP 1.1) require a Host header in the HTTP request, because many website domains can share the same IP address.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Nov 2009 02:16:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-url-logging/m-p/1321545#M417659</guid>
      <dc:creator>roderickm</dc:creator>
      <dc:date>2009-11-20T02:16:12Z</dc:date>
    </item>
    <item>
      <title>Re: ASA url logging</title>
      <link>https://community.cisco.com/t5/network-security/asa-url-logging/m-p/1321546#M417660</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Roderick,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your reply - so is there a way to get the ASA to log the url or is it dependant on how the website is constructed?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Nov 2009 09:54:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-url-logging/m-p/1321546#M417660</guid>
      <dc:creator>scottwilliamson</dc:creator>
      <dc:date>2009-11-20T09:54:42Z</dc:date>
    </item>
    <item>
      <title>Re: ASA url logging</title>
      <link>https://community.cisco.com/t5/network-security/asa-url-logging/m-p/1321547#M417661</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Scott, I'm not aware of a way to log the Host header of an HTTP request using the ASA. Panos' reply to this thread seems more informative to that end, saying that this enhancement request is CSCdt32288 but is not on the roadmap. I would also use this feature if the ASA were not overly burdened by enabling it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you absolutely must log the entire HTTP request, you may need to consider a different solution to meet that need. A sniffer with appropriate filters, an HTTP-aware IDS (snort.org), or a web filtering product could all handle this easily.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Nov 2009 13:54:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-url-logging/m-p/1321547#M417661</guid>
      <dc:creator>roderickm</dc:creator>
      <dc:date>2009-11-20T13:54:43Z</dc:date>
    </item>
    <item>
      <title>Re: ASA url logging</title>
      <link>https://community.cisco.com/t5/network-security/asa-url-logging/m-p/1321548#M417662</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well, I spoke too soon. Here's a method to log the entire request, with Host and URI. I found this on the &lt;A href="http://www.mail-archive.com/ccie_security@onlinestudylist.com/msg01633.html"&gt;CCIE_Security mailing list archive&lt;/A&gt;. Basically, you set up a regex to match the sites you wish to log. I used a simple dot "." to match anything.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE&gt;&lt;STRONG style="font-family: courier new,courier; "&gt;regex matchall "."&lt;BR /&gt;!&lt;BR /&gt;class-map type regex match-any DomainLogList&lt;BR /&gt; match regex matchall&lt;BR /&gt;class-map type inspect http match-all LogDomainsClass&lt;BR /&gt; match request header host regex class DomainLogList&lt;BR /&gt;class-map inspection_default&lt;BR /&gt; match default-inspection-traffic&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect http http_inspection_policy&lt;BR /&gt; parameters&lt;BR /&gt; class LogDomainsClass&lt;BR /&gt;&amp;nbsp; log &lt;BR /&gt;&lt;/STRONG&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then check your logging:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: courier new,courier; "&gt;&lt;SPAN&gt;Nov 20 09:27:08 10.19.30.10 asa %ASA-5-304001: 192.168.200.2 Accessed URL 157.166.255.19:&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://cnn.com/"&gt;http://cnn.com/&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Nov 20 09:27:08 10.19.30.10 asa %ASA-5-304001: 192.168.200.2 Accessed URL 157.166.226.26:&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cnn.com/"&gt;http://www.cnn.com/&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Nov 20 09:27:08 10.19.30.10 asa %ASA-5-304001: 192.168.200.2 Accessed URL 198.78.220.126:&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://i.cdn.turner.com/cnn/.element/css/3.0/common.css"&gt;http://i.cdn.turner.com/cnn/.element/css/3.0/common.css&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Nov 20 09:27:08 10.19.30.10 asa %ASA-5-304001: 192.168.200.2 Accessed URL 198.78.220.126:&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://i.cdn.turner.com/cnn/.element/css/3.0/main.css"&gt;http://i.cdn.turner.com/cnn/.element/css/3.0/main.css&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Beware -- this logs every HTTP request that the ASA sees. I have no idea how much load this places on an ASA with significant HTTP traffic. As described in the linked mailing list post, you may create more specific regex lists to match specific Hosts and/or URIs, and may take actions other than logging, including blocking/resetting.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Nov 2009 15:36:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-url-logging/m-p/1321548#M417662</guid>
      <dc:creator>roderickm</dc:creator>
      <dc:date>2009-11-20T15:36:06Z</dc:date>
    </item>
    <item>
      <title>Re: ASA url logging</title>
      <link>https://community.cisco.com/t5/network-security/asa-url-logging/m-p/1321549#M417663</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Roderick,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This looks very promising - I'll give it a go on our spare ASA and let you know&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hopefully my limited experience on the ASA will still allow me emulate your config&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;best Regards&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Nov 2009 15:47:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-url-logging/m-p/1321549#M417663</guid>
      <dc:creator>scottwilliamson</dc:creator>
      <dc:date>2009-11-20T15:47:07Z</dc:date>
    </item>
    <item>
      <title>Re: ASA url logging</title>
      <link>https://community.cisco.com/t5/network-security/asa-url-logging/m-p/1321550#M417664</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi again,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've configured the regex matchall etc this morning and I'm afraid nothing appears in the logs - I'm starting with an ASA config "out of the box" so maybe I'm missing something, though I have enabled logging .....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;logging enable&lt;BR /&gt;logging timestamp&lt;BR /&gt;logging standby&lt;BR /&gt;logging list Weblog message 304001&lt;BR /&gt;logging console Weblog&lt;BR /&gt;logging buffered debugging&lt;BR /&gt;logging history Weblog&lt;BR /&gt;logging facility 21&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the "Weblog" entries are from the NAC guest server / ASA url stuff mentioned in my original post.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Nov 2009 11:36:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-url-logging/m-p/1321550#M417664</guid>
      <dc:creator>scottwilliamson</dc:creator>
      <dc:date>2009-11-23T11:36:06Z</dc:date>
    </item>
    <item>
      <title>Re: ASA url logging</title>
      <link>https://community.cisco.com/t5/network-security/asa-url-logging/m-p/1321551#M417665</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Folks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas would be welcome - I feel that with your help this is very close to being resolved.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many Thanks&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Nov 2009 11:32:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-url-logging/m-p/1321551#M417665</guid>
      <dc:creator>scottwilliamson</dc:creator>
      <dc:date>2009-11-27T11:32:03Z</dc:date>
    </item>
    <item>
      <title>Re: ASA url logging</title>
      <link>https://community.cisco.com/t5/network-security/asa-url-logging/m-p/1321552#M417666</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Scott,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have my ASA sending logs to a syslog server. Here is my ASA logging:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;logging enable&lt;BR /&gt;logging timestamp&lt;BR /&gt;logging trap debugging&lt;BR /&gt;logging host inside x.x.x.x&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My syslog server is setup to only receive NOTICE events from the ASA. However, I'm now stuck where Scott was in his original post. It's logging the IP and URI, but isn't showing the actual host. I'm running 8.0(4). Here's what I see in my logs:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dec&amp;nbsp; 9 10:07:27 10.0.0.1 Dec 09 2009 08:07:05: %ASA-5-304001: 10.0.8.108 Accessed URL 208.80.152.3:/wikipedia/en/b/bc/Wiki.png&lt;BR /&gt;Dec&amp;nbsp; 9 10:07:27 10.0.0.1 Dec 09 2009 08:07:05: %ASA-5-415008: HTTP - matched Class 30: LogDomainsClass in policy-map http_inspection_policy, header matched from inside:10.0.8.108/1512 to outside: 208.80.152.3/80&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is a snippet from my running config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regex matchall "."&lt;/P&gt;&lt;P&gt;class-map type regex match-any DomainLogList&lt;BR /&gt; match regex matchall&lt;/P&gt;&lt;P&gt;class-map type inspect http match-all LogDomainsClass&lt;BR /&gt; match request header host regex class DomainLogList&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;BR /&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type inspect http http_inspection_policy&lt;BR /&gt; description http_inspection_policy&lt;BR /&gt; parameters&lt;BR /&gt;&amp;nbsp; protocol-violation action drop-connection&lt;BR /&gt; match request method connect&lt;BR /&gt;&amp;nbsp; drop-connection log&lt;BR /&gt; class LogDomainsClass&lt;BR /&gt;&amp;nbsp; log&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map inside-policy&lt;BR /&gt; class inside-classAccept&lt;BR /&gt;&amp;nbsp; inspect http http_inspection_policy&lt;BR /&gt; class inside-class&lt;BR /&gt;&amp;nbsp; inspect http http_inspection_policy&lt;BR /&gt; class inspection_default&lt;BR /&gt;&amp;nbsp; inspect http&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Was this a feature added in a later firmware? If so, I'll make the upgrade.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Dec 2009 16:05:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-url-logging/m-p/1321552#M417666</guid>
      <dc:creator>ronniekendrick</dc:creator>
      <dc:date>2009-12-09T16:05:09Z</dc:date>
    </item>
    <item>
      <title>Re: ASA url logging</title>
      <link>https://community.cisco.com/t5/network-security/asa-url-logging/m-p/1321553#M417667</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ronald,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;from sh version "System image file is "disk0:/asa821-k8.bin" - is there a feature that is missing from our respective ASAs that the others have?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I doubt it but I cannot see what I've missed from the config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Dec 2009 15:17:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-url-logging/m-p/1321553#M417667</guid>
      <dc:creator>scottwilliamson</dc:creator>
      <dc:date>2009-12-14T15:17:51Z</dc:date>
    </item>
    <item>
      <title>Re: ASA url logging</title>
      <link>https://community.cisco.com/t5/network-security/asa-url-logging/m-p/1321554#M417668</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Any new news on this issue?&amp;nbsp; I haven't been able to get the ASA (running version 8.2(1)) to log the hostname using any of the techniques above.&amp;nbsp; However, if you look at this cisco.com page, it indicates indirectly that this is meant to work, simply by adding "inspect http" to class inspection_default.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/ps6128/products_configuration_example09186a0080ac2fda.shtml#asac"&gt;http://www.cisco.com/en/US/products/ps6128/products_configuration_example09186a0080ac2fda.shtml#asac&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;The &lt;STRONG&gt;inspect http&lt;/STRONG&gt; command is placed under a
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; class-map within a policy-map. When enabled with the
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;service-policy&lt;/STRONG&gt; command, http inspection logs Get
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; requests with syslog message 304001. ASA code 8.0.4.24 or later is required for
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; syslog message 304001 to show the hostname as part of the URL. &lt;/PRE&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm baffled.&amp;nbsp; It is hard to believe this should be so difficult.&amp;nbsp; How else are you supposed to log web usage without 3rd party products or a proxy server?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Feb 2010 18:48:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-url-logging/m-p/1321554#M417668</guid>
      <dc:creator>claytonchumby</dc:creator>
      <dc:date>2010-02-22T18:48:11Z</dc:date>
    </item>
    <item>
      <title>Re: ASA url logging</title>
      <link>https://community.cisco.com/t5/network-security/asa-url-logging/m-p/1321555#M417669</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have been trying to get URL Logging to work too. I have found that if I browse to one of out internal sites it will log the URL name but if I go to a external site it will log the IP Address .&lt;/P&gt;&lt;P&gt;Has anyone gotten this to work for external sites?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Accessed URL 63.69.72.58:/js/pass.html?cb=23844&lt;BR /&gt;Accessed URL 96.17.72.144:/_media/uac/anatp.html?t=160afrf1088k4h&amp;amp;s=99999,&lt;BR /&gt;Accessed URL 64.236.79.229:/adcedge/lb?site=695501&amp;amp;betr=tc=1,99999,52588,5&lt;BR /&gt;Accessed URL 69.31.116.120:/assets/images/home/icons/video.gif&lt;BR /&gt;Accessed URL 216.246.75.227:/rsrc.php/zx/r/DmvbpGB-fMy.swf&lt;BR /&gt;Accessed URL 66.220.146.32:/extern/login_status.php?api_key=61b68b0702fb92&lt;BR /&gt;Accessed URL 209.234.252.57:/js/api_lib/v0.4/XdCommReceiver.js?v2&lt;BR /&gt;Accessed URL &lt;A href="http://www.expresspros.com:/"&gt;www.expresspros.com:/&lt;/A&gt;&lt;BR /&gt;Accessed URL &lt;A href="http://www.expresspros.com:/shared/style/ie.css"&gt;www.expresspros.com:/shared/style/ie.css&lt;/A&gt;&lt;BR /&gt;Accessed URL &lt;A href="http://www.expresspros.com:/shared/javascript/swfobject.js"&gt;www.expresspros.com:/shared/javascript/swfobject.js&lt;/A&gt;&lt;BR /&gt;Accessed URL &lt;A href="http://www.expresspros.com:/shared/javascript/thickbox.js"&gt;www.expresspros.com:/shared/javascript/thickbox.js&lt;/A&gt;&lt;BR /&gt;Accessed URL &lt;A href="http://www.expresspros.com:/shared/javascript/jquery-1-2-3-min.js"&gt;www.expresspros.com:/shared/javascript/jquery-1-2-3-min.js&lt;/A&gt;&lt;BR /&gt;Accessed URL &lt;A href="http://www.expresspros.com:/shared/images/socialmedia/twitter-sm.gif"&gt;www.expresspros.com:/shared/images/socialmedia/twitter-sm.gif&lt;/A&gt;&lt;BR /&gt;Accessed URL 74.125.67.138:/ga.js&lt;BR /&gt;Accessed URL &lt;A href="http://www.expresspros.com:/favicon.ico"&gt;www.expresspros.com:/favicon.ico&lt;/A&gt;&lt;BR /&gt;Accessed URL 199.7.57.72:/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRsK8Var42Wv2Ct%2BB&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 07 Nov 2010 13:19:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-url-logging/m-p/1321555#M417669</guid>
      <dc:creator>dedmundson</dc:creator>
      <dc:date>2010-11-07T13:19:48Z</dc:date>
    </item>
  </channel>
</rss>

