Software Secure Access
Activity Manage

Cisco Secure Access Help Manage Logging Log Formats and Versioning Cloud Firewall Log Formats Example

Last updated: Aug 07, 2025

Example

This is an example of a v12 Cloud Firewall log:

timestamp,origin IDs,identities,identity type,direction,protocol,packet size,source IP,source port,destination IP,destination port,data center,rule ID,action,fqdns,destination list IDs,first packet timestamp,last packet timestamp,packets sent,packets received,bytes sent,bytes received,fw event id,destination country,aws region,app id,private app group id,private flow,posture id,casi category ids,traffic source,content category ids,content category list ids,organization id,egress IP,egress
"2024-06-14 18:59:57","\[211039844\]","Passive Monitor", "CDFW Tunnel Device","OUTBOUND","1","84","172.17.3.4","60951","146.112.255.129","443","ams1.edc","12","ALLOW","google.com,apple.com","44,66","1718391597","1718391597","3","3","1108","755","39-42","","","","","","","[]","","","","2204063","3.3.3.4","TRUE"