Software Secure Access
Activity Manage

V12 Log Formats

The CSV fields in the header row of the DNS logs.

timestamp,most granular identity,identities,internal ip,external ip,action,query type,response code,domain,categories,most granular identity type,identity types,blocked categories,rule id,destination countries,organization id

The description of each field and the log version in which each field was released, up to Version 12. For more information about log versions, see Find Your Log Schema Version.

Field name Description Release version
timestamp The date and time of the DNS event, expressed as a UTC-formatted string (e.g., 2024-01-16 17:48:41).

 
Unlike the Secure Access dashboard and reports, Secure Access logs do not convert the timestamp to your local timezone.
v8
most granular identity The first identity matched with this request in order of granularity. v8
identities All identities associated with this request. v5
internal ip The internal IP address that made the request. v8
external ip The external IP address that made the request. v8
action Whether the request was allowed or blocked. v8
query type The type of DNS request that was made. v8
response code The DNS return code for this request. v8
domain The domain that was requested. v8
categories The security or content categories that the destination matches. For category definitions, see Manage Threat Categories and Manage Content Category Lists. v8
most granular identity type The first identity type matched with this request in order of granularity. v3
identity types The type of identity that made the request, for example: Roaming Computer, Network. v3
blocked categories The categories that resulted in the destination being blocked. v4
rule id The ID of the access rule when the DNS request is matched by a policy. v10
destination countries The two-character country identifier of the domain that was requested. v10
organization id The Secure Access organization ID. For more information, see Find Your Organization ID. v10