Cisco Cisco Web Security Appliance S670 Mode D'Emploi
13-18
Cisco IronPort AsyncOS 7.7 for Web User Guide
Chapter 13 Data Security and External DLP Policies
Logging
describes the Data Security Log fields.
Note
To learn when data transfer, such as a POST request, to a site was blocked by the external DLP server,
search for the IP address or hostname of the DLP server in the access logs.
search for the IP address or hostname of the DLP server in the access logs.
Table 13-3
Data Security Log Fields
Field Value
Description
Mon Mar 30 03:02:13 2009 Info:
Timestamp and trace level
303
Transaction ID
10.1.1.1
Source IP address
-
User name
-
Authorized group names
<<bar,text/plain,5120><foo,text/
plain,5120>>
File name, file type, file size for each file uploaded at once
Note: This field does not include text/plain files that are
less than the configured minimum request body size, the
default of which is 4096 bytes. For more information on
configuring the minimum request body size, see
less than the configured minimum request body size, the
default of which is 4096 bytes. For more information on
configuring the minimum request body size, see
.
BLOCK_WEBCAT_IDS-allowall-
DefaultGroup-DefaultGroup-NONE-
DefaultRouting
Cisco IronPort Data Security Policy and action
ns
Web reputation score
server.com
Outgoing URL
nc
URL category