Software Secure Access
Activity Manage

Cisco Secure Access Help Manage Logging Log Formats and Versioning Zero Trust Access Flow Log Formats Example

Last updated: Aug 07, 2025

Example

This is an example of a v12 Zero Trust Access flow log event:

timestamp,identity email,identity labels,identity type labels,organization id,msp organization id,hostname,transaction ID,private resource id,private resource group id,app connector id,app connector group id,ruleset id,rule id,connection status,connection failure reason,headend type,event type,rxbytes,txbytes,egress ip,egress port,nt group id,zta source port,enforced by,ftd enforcement id,ftd enforcement name
"2025-10-02 23:52:53","network@example.com","network@example.com, Network. AD Computer","Networks","ts-auto.com","1234567","1254367","Gd2o4Dr9PBERUpCvvAneaKbBqA6Di4Io","45937","45873","147","56","TERMINATED","App did not respond","CLAP","129","CONN_FAILURE","453","7756","1.1.1.1","3000","256","4001","FTD","12321321312","","