Zero Trust Access Enrollment Log Format
The Cisco Secure Access Zero Trust Access (ZTA) flow logs provide a detailed account of events relating to ZTA services. From version 13, Secure Access introduces a new log format specifically designed for ZTA enrollment events. These logs capture the details of enrollment and unenrollment transactions, enabling administrators to monitor the enrollment process and troubleshoot potential issues effectively.
Example
This is an example of a v13 ZTA enrollment log event:
timestamp,identity email,identity labels,identity type labels,organization id,msp organization id,enrollment id,event type,enrollment method,event detail,os type & version,zta client version,event status,device id,public ip
"2017-10-02 23:52:53","tom@abc.com","tom@abc.com", "Network". "AD Computer","Networks","ts-auto.com","1234567","1234567","Gd2o4Dr9PBERUpCvvAneaKbBqA6Di4Io","ENROLL","SAML","Failed to enroll","Mac OS 10.9.5","5.1.0.0","Successfully enrolled","12345","1.1.1.1"