Home page logo

educause logo Educause Security Discussion mailing list archives

Re: capturing full URL information via DNS request logs
From: Philip Webster <p.webster () QUT EDU AU>
Date: Thu, 10 Oct 2013 10:26:58 +1000

On 10/10/2013 08:03, John Ladwig wrote:
Cisco's ASA firewall line also logs http URIs at Informational priority.

We looked at the ASA a while back and it seemed that it would only log
the first URI in a connection. So we could see that a user went to
http://www.google.com/, for example, however if they maintained a
persistent HTTP connection then we wouldn't see the following search

Have you encountered this, and if so are you aware of a solution?
Philip Webster
Senior IT Security Engineer | Queensland University of Technology

  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]