You can view the details for a URL that is inspected by the Sensor in the Manager. The Manager dashboard provides Top Risky URLs and Top Endpoints Using Risky URLs monitors to view the details of URL reputation.
Viewing Top Risky URLs
You can view the top risky URLs that are accessed from your systems. To view the top risky URLs, perform the following steps:
Select the Dashboard tab in the Manager.
Click
to edit the dashboard settings. The Dashboard Settings window opens.Select Top Risky URLs monitor.
Click OK. The Top Risky URLs monitor is visible on the Dashboard.
.png)
Click on the graph bar that displays the number of connections. The Attack Log window opens.
Double click on an alert to view the details of the risky URL.
Viewing Top Endpoints Using Risky URLs
You can view the top endpoint systems that are sending requests to risky URLs. To view the top endpoints that sending requests to risky URLs, perform the following steps:
Select the Dashboard tab in the Manager.
Click
to edit the dashboard settings. The Dashboard Settings window opens.Select Top Endpoints Using Risky URLs monitor.
Click OK. The Top Endpoints Using Risky URLs monitor is visible on the Dashboard.
.png)
Click on the graph bar that displays the number of connections. The Attack Log window opens.
Double click on an alert to view the details of the risky URL.
Viewing URL reputation alert details in Attack Log
You can view the alert details of a risky URL in the Attack Log page.
.png)
When you double-click on an alert, the alert details window opens. The Layer 7 section of the alert details has the following information:
Risky URL
Risk category
The header fields that are used to construct the URL
.png)