SLS -> Explore -> Firewall/URL “Is Decrypted” showing false when firewalls showing DECRYPTED field showing yes

SLS -> Explore -> Firewall/URL “Is Decrypted” showing false when firewalls showing DECRYPTED field showing yes

808
Created On 02/13/25 01:09 AM - Last Modified 12/12/25 03:11 AM


Symptom


  • On Strata Logging Service the "Is Decrypted” field reports false when firewall or Panorama shows the session being decrypted for the same URL
    • On SLS >Explore >Firewall/URL >”Is Decrypted” reported false
    • On Firewall or Panorama Monitor >URL Filtering shows the session decrypted for the same URL. 


Environment


  • NGFW
  • Prisma Access(SASE)
  • Supported PAN-OS
  • Strata Logging Service (SLS)


Cause


Due to the current SLS design, “Is Decrypted” field is applicable to Firewall/Traffic type and not for Firewall/URL type.



Resolution


  1. This is a known behavior.
  2. For Strata Logging Service,  SLS->Explore -> Firewall/URL field “Is Proxy” (is_proxy) should be referred.
  3. This field is reported as true if the firewall Monitor->URL Filtering session shows “yes” for DECRYPTED field.
  4. The Best practice is to set the filter to “Is Proxy” field for URL type.
  5. The field “Is Decrypted” should be referred only for SLS -> Explore->Firewall/Traffic type. 


    Additional Information


    DIT-22298



    Actions
    • Print
    • Copy Link

      https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000sdOPCAY&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail