Skip to main content
Skip table of contents

Web Secure Event

Vendor Documentation


Rule NameRule TypeClassificationCommon Event
Web Secure EventBase RuleActivityGeneral Web Access
File Scan Result : UnknownSub RuleActivityPotentially Threatening File Observed
File Scan Result : CleanSub RuleActivityGeneral Threat Message
File Scan Result : MaliciousSub RuleMalwareDetected Malware Activity

Mapping with LogRhythm Schema

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
N/AN/AN/ATimestamp since UNIX epoch.
N/A<milliseconds>NumberElapsed time (latency) in milliseconds.
N/A<sip>IP Address

Client IP address.

You can choose to mask the IP address in the access logs using the advancedproxyconfig > authentication CLI command.

N/AN/AN/ATransaction result code.

For more information, see W3C Compliant Access Log Files.
N/A<responsecode>NumberHTTP response code.
N/A<size>NumberResponse size (headers + body).

First line of the request.

When the first line of the request is for a native FTP transaction, some special characters in the file name are URL encoded in the access logs. For example, the “@” symbol is written as “%40” in the access logs.

The following characters are URL encoded:

& # % + , : ; = @ ^ { } [ ]


Authenticated username.

You can choose to mask the username in the access logs using the advancedproxyconfig > authentication CLI command.


Code that describes which server was contacted for the retrieving the request content.

The most common values include:

  • NONE. The Web Proxy had the content, so it did not contact any other server to retrieve the content.
  • DIRECT. The Web Proxy went to the server named in the request to get the content.
  • DEFAULT_PARENT. The Web Proxy went to its primary parent proxy or an external DLP server to get the content.
N/AN/AN/AData source or server IP address.
N/AN/AN/AResponse body MIME type.

ACL decision tag.

The end of the ACL decision tag includes a dynamically generated number that the Web Proxy uses internally. You can ignore this number.

For more information, see ACL Decision Tags.


Name of policy group responsible for the final decision on this transaction (Access Policy, Decryption Policy, or Data Security Policy). When the transaction matches a global policy, this value is “DefaultGroup.”

Any space in the policy group name is replaced with an underscore ( _ ).


Identity policy group name.

Any space in the policy group name is replaced with an underscore ( _ ).


Outbound Malware Scanning Policy group name.

Any space in the policy group name is replaced with an underscore ( _ ).


Cisco Data Security Policy group name. When the transaction matches the global Cisco Data Security Policy, this value is “DefaultGroup.” This policy group name only appears when Cisco Data Security Filters is enabled. “NONE” appears when no Data Security Policy was applied.

Any space in the policy group name is replaced with an underscore ( _ ).


External DLP Policy group name. When the transaction matches the global External DLP Policy, this value is “DefaultGroup.” “NONE” appears when no External DLP Policy was applied.

Any space in the policy group name is replaced with an underscore ( _ ).


Routing Policy group name, displayed as ProxyGroupName/ProxyServerName.

When the transaction matches the global Routing Policy, this value is “DefaultRouting.” When no upstream proxy server is used, this value is “DIRECT.”

Any space in the policy group name is replaced with an underscore ( _ ).

N/AN/AN/AThe custom URL category assigned to the transaction, abbreviated. This field shows “nc” when no category is assigned.
N/AN/AN/AWeb Reputation filters score. This field either shows the score as a number, “ns” for no score, or “dns” when there is a DNS lookup error.

The malware scanning verdict Webroot passed to the DVS engine. Applies to responses detected by Webroot only.

For more information, see Malware Scanning Verdict Values.

N/AN/AN/AName of the spyware that is associated with the object. Applies to responses detected by Webroot only.
N/AN/AN/AThe Webroot specific value associated with the Threat Risk Ratio (TRR) value that determines the probability that malware exists. Applies to responses detected by Webroot only.
N/AN/AN/AA value that Webroot uses as a threat identifier. Cisco Customer Support may use this value when troubleshooting an issue. Applies to responses detected by Webroot only.
N/AN/AN/AA value that Webroot uses as a trace identifier. Cisco Customer Support may use this value when troubleshooting an issue. Applies to responses detected by Webroot only.

The malware scanning verdict McAfee passed to the DVS engine. Applies to responses detected by McAfee only.

For more information, see Malware Scanning Verdict Values.

N/AN/AN/AThe name of the file McAfee scanned. Applies to responses detected by McAfee only.
N/AN/AN/AA value that McAfee uses as a scan error. Cisco Customer Support may use this value when troubleshooting an issue. Applies to responses detected by McAfee only.
N/AN/AN/AA value that McAfee uses as a detection type. Cisco Customer Support may use this value when troubleshooting an issue. Applies to responses detected by McAfee only.
N/AN/AN/AA value that McAfee uses as a virus type. Cisco Customer Support may use this value when troubleshooting an issue. Applies to responses detected by McAfee only.
N/AN/AN/AThe name of the virus that McAfee scanned. Applies to responses detected by McAfee only.

The malware scanning verdict Sophos passed to the DVS engine. Applies to responses detected by Sophos only.

For more information, see Malware Scanning Verdict Values.

N/AN/AN/AA value that Sophos uses as a scan return code. Cisco Customer Support may use this value when troubleshooting an issue. Applies to responses detected by Sophos only.
N/AN/AN/AThe name of the file in which Sophos found the objectionable content. Applies to responses detected by Sophos only.
N/AN/AN/AA value that Sophos uses as the threat name. Cisco Customer Support may use this value when troubleshooting an issue. Applies to responses detected by Sophos only.
N/AN/AN/AThe Cisco Data Security scan verdict based on the action in the Content column of the Cisco Data Security Policy. The following list describes the possible values for this field:
  • 0. Allow
  • 1. Block
  • - (hyphen). No scanning was initiated by the Cisco Data Security Filters. This value appears when the Cisco Data Security Filters are disabled, or when the URL category action is set to Allow.
N/AN/AN/AThe External DLP scan verdict based on the result given in the ICAP response. The following list describes the possible values for this field:
  • 0. Allow
  • 1. Block
  • - (hyphen). No scanning was initiated by the external DLP server. This value appears when External DLP scanning is disabled, or when the content was not scanned due to an exempt URL category on the External DLP Policies > Destinations page.

The predefined URL category verdict determined during request-side scanning, abbreviated. This field lists a hyphen (-) when URL filtering is disabled.

For a list of URL category abbreviations, see URL Category Descriptions.


The URL category verdict determined by the Dynamic Content Analysis engine during response-side scanning, abbreviated. Applies to the Cisco Web Usage Controls URL filtering engine only. Only applies when the Dynamic Content Analysis engine is enabled and when no category is assigned at request time (a value of “nc” is listed in the request-side scanning verdict).

For a list of URL category abbreviations, see URL Category Descriptions.

N/A<threatname>Text/StringUnified response-side anti-malware scanning verdict that provides the malware category independent of which scanning engines are enabled. Applies to transactions blocked or monitored due to server response scanning.
N/AN/AN/AThe threat type returned by the Web Reputation filters which resulted in the target website receiving a poor reputation. Typically, this field is populated for sites at reputation of -4 and below.
N/AN/AN/AThe application name as returned by the AVC engine, if applicable. Only applies when the AVC engine is enabled.
N/AN/AN/AThe application type as returned by the AVC engine, if applicable. Only applies when the AVC engine is enabled.
N/AN/AN/AThe application behavior as returned by the AVC engine, if applicable. Only applies when the AVC engine is enabled.

Safe browsing scanning verdict. This value indicates whether either the safe search or the site content ratings feature was applied to the transaction.

For a list of the possible values, see Logging Adult Content Access.

N/AN/AN/AThe average bandwidth consumed serving the request, in Kb/sec.
N/AN/AN/AA value that indicates whether the request was throttled due to bandwidth limit control settings, where “1” indicates the request was throttled, and “0” indicates it was not.
N/AN/AN/AThe type of user making the request, either “[Local]” or “[Remote].” Only applies when AnyConnect Secure Mobility is enabled. When it is not enabled, the value is a hyphen (-).
N/AN/AN/AUnified request-side anti-malware scanning verdict independent of which scanning engines are enabled. Applies to transactions blocked or monitored due to client request scanning when an Outbound Malware Scanning Policy applies.

The threat name assigned to the client request that was blocked or monitored due to an applicable Outbound Malware Scanning Policy.

This threat name is independent of which anti-malware scanning engines are enabled.

N/AN/AN/AVerdict from Advanced Malware Protection file scanning:

0: File is not malicious
1: File was not scanned because of its file type
2: File scan timed out
3: Scan error
Greater than 3: File is malicious
N/AN/AN/AThreat name, as determined by Advanced Malware Protection file scanning; "-" indicates no threat.

Reputation score from Advanced Malware Protection file scanning. This score is used only if the cloud reputation service is unable to determine a clear verdict for the file.

For details, see information about the Threat Score and the reputation threshold in File Reputation Filtering and File Analysis.


Indicator of upload and analysis request:

“0” indicates that Advanced Malware Protection did not request upload of the file for analysis.

“1” indicates that Advanced Malware Protection did request upload of the file for analysis.

N/A<objectname>Text/StringThe name of the file being downloaded and analyzed.
N/A<hash>Text/StringThe SHA-256 identifier for this file.
Text/StringVerdict from the AMP reputation server for the file:

1 – Unknown
2 – Clean
3 – Malicious
4 – Unscannable
N/AN/AN/AArchive scan Verdict.
N/AN/AN/AArchive scan Verdict Detail. If an Inspectable Archive file is blocked (ARCHIVESCAN_BLOCKEDFILETYPE) based on Access Policy: Custom Objects Blocking settings, this Verdict Detail entry includes the type of file blocked, and the name of the blocked file.
N/A<useragent>Text/StringSuspect user agent.
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.