Hi,
If you are using stream mode logging and sending your traffic logs to a syslog server, match the logs on the server with "RT_UTM" and you will be able to see all activities of the UTM on traffic including blocked and permitted URLs.
If you are storing the traffic logs on the RE, match them using :-
set system syslog file utm-logs any any set system syslog file utm-logs match "RT_UTM"
Hope this helps !
Regards,
Sahil Sharma