Example
This is an example of a v12 Zero Trust Access flow log event:
timestamp,identity email,identity labels,identity type labels,organization id,msp organization id,hostname,transaction ID,private resource id,private resource group id,app connector id,app connector group id,ruleset id,rule id,connection status,connection failure reason,headend type,event type,rxbytes,txbytes,egress ip,egress port,nt group id,zta source port,enforced by,ftd enforcement id,ftd enforcement name
"2025-10-02 23:52:53","network@example.com","network@example.com, Network. AD Computer","Networks","ts-auto.com","1234567","1254367","Gd2o4Dr9PBERUpCvvAneaKbBqA6Di4Io","45937","45873","147","56","TERMINATED","App did not respond","CLAP","129","CONN_FAILURE","453","7756","1.1.1.1","3000","256","4001","FTD","12321321312","","