Software Secure Access
Activity Manage

Cisco Secure Access Help Manage Logging Log Formats and Versioning IPS Log Formats Example

Last updated: Aug 07, 2025

Example

This is an example of a v12 IPS log:

timestamp,identities,identity types,generator id,signature id,signature message,signature list id,severity,attack classification,cves,ip protocol,session id,source ip,source port,destination ip,destination port,action,operation mode,policy resource id,direction,firewall rule id,ips config type,aws region,application id,casi category ids,data center,organization id,egress ip,egress,enforced by,ftd enforcement id,ftd enforcement name
"2024-09-11 23:17:13","Firewall Tunnel Name","Network Tunnels","1","16606","SERVER-ORACLE BEA WebLogic Server Plug-ins Certificate overflow attempt","50516","HIGH","Attempted User Privilege Gain","cve-2009-1016","TCP","12345","123.123.123.123","80","1.1.1.1","40762","Would Block","IDS","50516","S2C","21171","PROFILE","eu-central-2b","","","","8151514","3.3.3.4","TRUE","FTD","12321321312",""