Cisco Cisco Web Security Appliance S160 User Guide

Page of 638
 
24-22
Cisco IronPort AsyncOS 7.5 for Web User Guide
Chapter 24      Logging
Access Log File
 describes the different fields in the scanning verdict information section of each access log 
file entry. 
Table 24-8
Access Log File Entry — Scanning Verdict Information 
Position and Format 
Specifier
Field Value
Description
position 1
%XC
IW_infr
The URL category assigned to the transaction, abbreviated. This field shows 
“nc” when no category is assigned.
For a list of URL category abbreviations, see 
.
position 2
%XW
ns
Web Reputation filters score. This field either shows the score as a number, 
“ns” for “no score,” or “dns” when there is a DNS lookup error.
position 3
%Xv
24
The malware scanning verdict Webroot passed to the DVS engine.
Applies to responses detected by Webroot only.
For more information, see 
position 4
“%Xn”
“Trojan-Phisher-Gamec
Name of the spyware that is associated with the object.
Applies to responses detected by Webroot only.
position 5
%Xt
0
The Webroot specific value associated with the Threat Risk Ratio (TRR) 
value that determines the probability that malware exists. 
Applies to responses detected by Webroot only.
position 6
%Xs
354385
A value that Webroot uses as a threat identifier. Cisco IronPort Customer 
Support may use this value when troubleshooting an issue.
Applies to responses detected by Webroot only.
position 7
%Xi
12559
A value that Webroot uses as a trace identifier. Cisco IronPort Customer 
Support may use this value when troubleshooting an issue.
Applies to responses detected by Webroot only.
position 8
%Xd
-
The malware scanning verdict McAfee passed to the DVS engine.
Applies to responses detected by McAfee only.
For more information, see 
position 9
“%Xe”
“-”
The name of the file McAfee scanned.
Applies to responses detected by McAfee only.
position 10
%Xf
-
A value that McAfee uses as a scan error. Cisco IronPort Customer Support 
may use this value when troubleshooting an issue.
Applies to responses detected by McAfee only.
position 11
%Xg
-
A value that McAfee uses as a detection type. Cisco IronPort Customer 
Support may use this value when troubleshooting an issue.
Applies to responses detected by McAfee only.
position 12
%Xh
-
A value that McAfee uses as a virus type. Cisco IronPort Customer Support 
may use this value when troubleshooting an issue.
Applies to responses detected by McAfee only.