Software Secure Access
Activity Manage

Firewall Event Details Fields

Firewall event details include the following fields that are also available as Activity Search report columns. For more information about these fields, see View and Customize the Activity Search Report.

  • Action
  • Time
  • Rule Name
  • Source
  • Destination IP
  • Categories
  • File Name
  • Protocol
  • Application Protocol

Firewall event details also include the following fields that do not appear as Activity Search report columns.

Field Name Description
Source IP The source IPv4 or IPv6 address. Supports both compressed and long-form IPv6 address formats.
Source Port The source port.
Destination Port The destination port.
Resource/Application The name of the resource or application.
File Status (Disposition) The file's Cisco AMP disposition: - Clean: Indicates that the AMP cloud categorized the file as clean. - Malware: Indicates that the AMP cloud categorized the file as malware, or local malware analysis identified malware. - Unknown: Indicates that the system queried the AMP cloud, but the AMP cloud has not assigned the file a disposition.
SHA256 Hash The checksum of the file, if available and the event matched rules with File Type Control or File Inspection enabled.
File Transfer Direction DOWNLOAD, UPLOAD, or UNKNOWN, if the event matched rules with File Type Control or File Inspection enabled.
Identified Threat The name of the detected malware.
Malware Analysis Detected If the event matched rules with File Inspection enabled, this field shows one of the following values as a result of file analysis by Cisco Secure Malware Analytics. For more information, see Enable File Analysis by Cisco Secure Malware Analytics. - UNKNOWN - NOT ANALYZED - ANALYSIS COMPLETE NO VIRUS - ANALYSIS FAILED - ANALYSIS COMPLETE MALWARE DETECTED
Threat Severity Score The threat score most recently associated with this file. This is a value from 0 to 100.
File Type Identifiers The type of file. For example, PDF or MSEXE.
File Size (bytes) The size of the file in bytes, if the event matched rules with File Type Control or File Inspection enabled.
Archive File Name The name of the archive file involved with the activity, if the event matched rules with File Type Control or File Inspection enabled.
Archive Extraction Depth The level (if any) at which the file was nested in an archive file.
Archive SHA-256 Hash The checksum of the archive file, if the event matched rules with File Type Control or File Inspection enabled.