Cisco Secure Access Help

PDF

Cisco Secure Access Help

Activity Search Report

Want to summarize with AI?

Log in

Describes Activity Search Report in Cisco Secure Access. The report lists all security (and non-security) activity for the sources reporting to Secure Access for the selected time.


The report lists all security (and non-security) activity for the sources reporting to Secure Access for the selected time. Use this report to find the result of every DNS, URL, and IPv4 or IPv6 request from your various sources in descending date and time.

You can also refine your search using filters to help identify security issues that require attention.


View and Customize the Activity Search Report


View the Activity Search Report

Procedure

  1. Navigate to Monitor > Reports > Activity Search. This takes you to the default view of the Activity Search report, which lists all of your identities and the internet requests or traffic events for your organization, tracked over time.


    You to the default view of the Activity Search report, which lists all of your identities and the internet requests or traffic events for your organization, tracked over time.

    The Activity Search report supports partial results if one or more event type queries (such as Proxy, Firewall, IP, Intrusion, or Decryption) fail due to an internal error. The report displays all available results from the successful queries, rather than showing an error for the entire request. Any unavailable event types will be clearly indicated in a message displayed on the screen.

    Note
    This feature update ensures continued visibility into available security data, even when certain backend services encounter issues. All retrieved data remains accessible for review and export.
  2. Hover over individual column values to apply it as a search filter or to exclude it from the search.

  3. To learn more about individual results, click the blue ellipsis View Actions icon to the right of each search result. For more information, see View Activity Search Report Actions.


Customize the Activity Search Report

Procedure

  1. Choose a time frame to view the report. The default is Last 24 Hours. The maximum is Last 30 Days.


    The Screenshot 2024 05 21 at 1 08 00 PM interface.
  2. Customize Columns to select columns to display, drag and drop to reorder column position, then click Apply.

    Column name Column description
    Request When All Requests is selected, this column displays the type of request for each event. Event request types are DNS, Web, Firewall, IPS, ZTNA Clientless, ZTNA Client-based, and Decryption.
    Source The name of the source of the request. Applicable to all request types.
    Rule Identity

    The identity of the source that Secure Access used to determine which rule applied to the request. Applicable to DNS, Web, Firewall, and ZTNA requests.

    A request can have multiple identities. Click the row to view Event Details including all identities associated with a request. For more information, refer to View Activity Search Report Actions.

    Destination The destination of the request. Applicable to DNS, Web, Firewall, IPS, and ZTNA requests.
    Destination IP The IPv4 or IPv6 address of the destination. Supports both compressed and long-form IPv6 address formats. Applicable to Web, Firewall, and Decryption requests.
    Destination Port The UDP/TCP port of the destination request. Applicable to client-based ZTA requests. For more information, refer to Comparison of Client-Based and Browser-Based Zero Trust Access Connections.
    Destination Country The two-character country identifier. Applicable to DNS, Web, and Firewall requests.
    File Name

    The name of the file involved with the activity, where applicable. Applicable to Web and Firewall requests.

    Note: File Name will only populate for traffic matching rules with File Type Control or File Inspection enabled (you can enable File Type Control without blocking any file types by clicking enable and saving the rule.) If none of the rules have File Type Control enabled, the file name and extension fields remain blank.

    Internal IP The internal IPv4 or IPv6 address of the request. Supports both compressed and long-form IPv6 address formats. Applicable to DNS and Web requests.
    External IP The external IPv4 or IPv6 address of the request. Supports both compressed and long-form IPv6 address formats. Applicable to DNS and Web requests.
    DNS Type The DNS record type. Applicable to DNS requests.
    Action

    The request is either Blocked or Allowed. Applicable to DNS, Web, Firewall, IPS, and ZTNA requests.

    Blocked – Certificate Error indicates certificate and TLS error events when the request is processed by a ruleset with HTTPS inspection and File Analysis enabled. Blocked – AI Supply Chain indicates end user attempts to download AI model files that are associated with prohibited suppliers, rely on a copyleft license, or can execute arbitrary code when the request is processed by an internet access rule with a security profile for internet access with AI Supply Chain Blocking enabled. For more information, refer to AI Supply Chain Report.

    Categories Content and Security categories flagged with the activity. Applicable to DNS, Web, and Firewall requests. Click Dispute Categorization in the Event Details navigation drawer to suggest a different category for a Source. The label, Block List appears when DNS traffic is blocked by an internet access rule with a specific destination list or destinations set to Any. Block List is a reporting label only and is not a separate manageable category or destination list.
    Resource/Application The resource or application involved with the activity, when applicable. Populates for traffic matching rules with Application Controls enabled. If no rules have Application Controls enabled, then the field will remain blank. Applicable to DNS, Web, Firewall, and ZTNA requests. For more information, refer to Advanced Application Controls.
    Signature List Name The Secure Access Intrusion Prevention System (IPS) signature list applied to the request. Applicable to IPS requests. For more information, refer to Manage IPS Profiles.
    IPS Signature The signature of the known threat that was blocked or logged by Secure Access IPS. Applicable to IPS requests. For more information, refer to Manage IPS Profiles.
    Protocol Displays whether the Web request protocol is HTTP or HTTPS, and whether the Firewall, IPS, or Decryption request protocol is TCP or UDP. Decryption request protocol includes the cryptographic protocol, such as TLS.
    Rule Name

    The name of the access rule applied to the request. Applicable to DNS, Web, Firewall, IPS, and ZTNA requests.

    Click the rule name to view your Access Policy where the rule is configured. For more information, refer to Manage the Access Policy.

    Click the row to view Event Details including details of the rule (such as destination list or schedule applied). For more information, refer to View Activity Search Report Actions.

    Application Category If an application is involved with the activity, this column contains the categories associated with the application. Applicable to DNS, Web, and Firewall requests. For the full list of application categories, refer to Application Categories.
    Application Protocol If an application is involved with the activity, this column contains the protocol for the application (HTTP, SSL, RTP, DNS, or none). Applicable to Firewall requests.
    Request Method The HTTP method used by the request. Applicable to Web requests.
    Referer The URI from which the request originated. Applicable to Web requests.
    Status Code Standard HTTP status codes. Applicable to Web requests.
    Content Type The HTTP content type. Applicable to Web requests.
    File Extension The extension of the file involved in the activity, where applicable. Applicable to Web and Firewall requests.
    OS The operating system of the client's device. Applicable to ZTNA requests.
    Browser The client's browser. Applicable to ZTNA requests.
    Location The two-character country identifier. Applicable to ZTNA requests.
    Location IP The IPv4 or IPv6 address of the client. Supports both compressed and long-form IPv6 address formats. Applicable to ZTNA requests.
    Date and Time The date and time stamp of the request. Applicable to all request types.
  3. Filter Request by selecting an option from the dropdown menu at the top right. Filters and columns update to those that are relevant to the selected Request type. The default Request type is All.


    The Activity Search Request Dropdown interface.
  4. Search and select additional Filters to the left of the report results. For the complete list of filters and options, see the table below.


    Type. The default Request type is All. Search and select additional Filters to the left of the report results. For the complete list of filters and options, see the table below.

    Choose from the following filters and options. Filter options available in this menu are determined by the Request selected in the previous step.

    Note
    Filters apply a logical OR relationship between options, except in the case Event Type. Selecting more than one Event Type option will not return results because the Event Type filter applies a logical AND relationship between options.

    For example, if you filter for both the Public Application and Destination List event types, the Activity Search report will not return any results because an event can have only one event type.

    For all other filters, selecting some or all options can return results. For example, if you filter for both the HTTP and HTTPS protocols, the Activity Search report will return all web events because they will have used either the HTTP OR HTTPS protocol.

    Filter Filter options
    Response

    Allowed

    Blocked

    Blocked PDNS

    The Response filter applies a logical OR relationship when you select more than one option. Optionally, you may apply one or both advanced options to the Allowed event filter:

    Allow: All events that were allowed by passing through your security policies. For Web Policies, this will include the Allow-Security enforced action.

    Security Overridden: Identities will be permitted to access destination even if we detect a security issue. This action will only appear on activity associated with Web Policies.

    Warn Page Behavior

    Warned

    Accessed After Warn

    The Warn Page Behavior filter applies a logical OR relationship when you select more than one option.

    Isolate Isolated events are browser-based security threats that were redirected to a Secure Access cloud-based host. For more information, refer to About Isolated Destinations.
    IPS Signature

    Log Only

    Would Block

    Block

    The IPS Signature filter applies a logical OR relationship when you select more than one option.

    Protocol

    HTTP

    HTTPS

    The Protocol filter applies a logical OR relationship when you select more than one option.

    Event Type

    Public Application

    Destination List

    Any Security Category

    Any Content Category

    Cisco AMP Disposition is Malicious

    Antivirus Disposition is Malicious

    Integration

    Tenant Controls

    Certificate and TLS Errors

    Data Loss Prevention

    Geolocations

    The Event Type filter applies a logical AND relationship when you select more than one option and will return only one type of event.

    Identity Type

    The type of source in the Rule Identity column. Identity Type options vary by event and by organization.

    The Identity Type filter applies a logical OR relationship when you select more than one option.

    Decryption Actions

    Decrypt Inbound

    Decrypt Outbound

    Do not Decrypt

    Decrypt Error

    The Decryption Actions filter applies a logical OR relationship when you select more than one option.

    Security Categories For the full list of filter options, see Threat Category Descriptions. The Security Categories filter applies a logical OR relationship when you select more than one option.
    Content Categories For the full list of filter options, see Available Content Categories. The Content Categories filter applies a logical OR relationship when you select more than one option.
  5. Select Search Options below the Filters menu in the previous step.

    • Include All Traffic — Includes data from all domains including noisy domains that are filtered out by default.

    • Filter by Uncategorized — Includes destinations that are not classified under a specific security or content category.




Save Activity Search Report columns and filters for future use

Procedure

  1. Once you select a filter on a new search, a Save Search button will appear. Configure filters and customize columns, then click Save Search.

  2. Review search filters applied to this search, then click Continue.

    A new search, a Save Search button will appear. Configure filters and customize columns, then click Save Search. Review search filters applied to this search, then click Continue.
  3. Review customized columns selected for display for this search, then click Continue.

    The Screenshot 2024 05 15 at 4 04 33 PM interface.
  4. Search name is required and Description is optional. Once you Save, you will be able to access and update your customized report from the Saved Searches dropdown at the top right of the report.

    Required and Description is optional. Once you Save, you will be able to access and update your customized report from the Saved Searches dropdown at the top right of the report.

Customize and Manage Saved Searches

The Activity Search Report supports enhanced customization and search management with the following functions:

  • Auto-Save of Search State: When you apply filters or customize columns, your current view is automatically saved. If you navigate away from the Activity Search Report and then return, your last auto saved state including filters and column selections is automatically restored.
  • Restore Options: Restore options will appear only when a previous state or changes exist to revert to. Restore options allow you to quickly revert your report view to a previous or default state.
    • Restore to default Layout: Revert the report to its original default view.
    • Restore to Previous State: Return to your last auto-saved view.

      This option is disabled if no previous state exists (such as on your first visit or before making changes).


View an Access Policy Rule from the Activity Search Report

You can seamlessly move from an activity record in the Activity Search report to the associated access policy rule. This feature enables faster investigation, troubleshooting, and policy tuning by allowing you inspect, view, or edit the rule that triggered a specific activity.

Procedure

  1. Navigate to Monitor > Reports > Activity Search.

  2. Use the filters and search bar to locate the activity you want to investigate in the Activity Search report. For more information, see Customize the Activity Search Report.

  3. In the Activity Search results, locate the activity record you want to investigate and click the View Actions (three-dot) menu for that record.

    Displays the menu that appears after clicking the View Actions (three-dot) icon in Activity Search, with options for View full details, View Rule, and Edit Rule.

    Choose one of the following options:

    • View full details: Opens the Event Details panel. In the Event Details panel, click the rule name to navigate to the Access Policy page with the associated rule filtered and highlighted.

      The Event details page showing a clickable rule name.

    • View Rule: Directly opens the Access Policy page with the relevant rule filtered and highlighted.

      The Access Policy page with the relevant rule filtered and highlighted.

    • Edit Rule: Opens the associated rule in edit mode, allowing you to modify its configuration as needed.

      The associated rule displayed in edit mode, allowing configuration changes.


View Firewall Events in Activity Search Report

The Activity Search report includes full details about Firewall requests that have been allowed or blocked by an Access Policy rule.

For more information about the Activity Search report, see View the Activity Search Report. For more information about your Access Policy rules, see Manage the Access Policy.

Note
File Name and other fields related to file inspection and file type controls will only populate for events involving file access that match private access rules with File Inspection or File Type Control enabled. If no private access rules have File Inspection or File Type Control enabled, the file name and extension fields will remain blank for events with the Firewall request type. For more information, see Get Started With Private Access Rules, Manage File Inspection and File Analysis, and Manage File Type Controls.

Filter the Report by Firewall Requests

Before you begin

A minimum user role of Read-only. For more information, see Manage Accounts.

Procedure

  1. Navigate to Monitor > Reports > Activity Search.

  2. Choose a time frame to view the report. You can view events from the last 24 hours (default), Yesterday , Last 7 Days, Last 30 Days, or a Custom range.

    The label FW in the Request column indicates a Firewall event.
  3. Select the Firewall option from the dropdown menu at the top right to filter the report for Firewall events. Columns and Filter options update to those that are relevant to Firewall events.


    Firewall option from the dropdown menu at the top right to filter the report for Firewall events. Columns and Filter options update to those that are relevant to Firewall events.
  4. Click the row to view Event Details.

    The Activity Search Report displays Event Details for each search result in a navigation drawer on the right. For more information, see View Activity Search Report Actions.

    Firewall event details include the following fields that are also available as Activity Search report columns. For more information about these fields, see View and Customize the Activity Search Report.

    • Action

    • Time

    • Rule Name

    • Source

    • Destination IP

    • Categories

    • File Name

    • Protocol

    • Application Protocol

    Firewall event details also include the following fields that do not appear as Activity Search report columns.

    Field Name Description
    Source IP The source IPv4 or IPv6 address. Supports both compressed and long-form IPv6 address formats.
    Source Port The network port number on the source host from which the request originated.
    Destination Port The TCP or UDP port number on the destination host to which the request was sent. This field identifies the specific service or application targeted by the connection (for example, port 80 for HTTP or port 443 for HTTPS).
    Resource/Application The name of the resource or application.
    Session Bytes Sent The total number of bytes sent during the Firewall session. This value is reported at session disconnect and reflects the cumulative amount of data sent from the source to the destination for the event session.
    Session Bytes Received The total number of bytes received during the Firewall session. This value is reported at session disconnect and reflects the cumulative amount of data received from the destination by the source for the event session.
    File Status (Disposition)

    The file's Cisco AMP disposition:

    • Clean: Indicates that the AMP cloud categorized the file as clean.

    • Malware: Indicates that the AMP cloud categorized the file as malware, or local malware analysis identified malware.

    • Unknown: Indicates that the system queried the AMP cloud, but the AMP cloud has not assigned the file a disposition.

    SHA256 Hash The checksum of the file, if available and the event matched rules with File Type Control or File Inspection enabled.
    File Transfer Direction DOWNLOAD, UPLOAD, or UNKNOWN, if the event matched rules with File Type Control or File Inspection enabled.
    Identified Threat The name of the detected malware.
    Malware Analysis Detected

    If the event matched rules with File Inspection enabled, this field shows one of the following values as a result of file analysis by Cisco Secure Malware Analytics. For more information, see Enable File Analysis by Cisco Secure Malware Analytics.

    • UNKNOWN

    • NOT ANALYZED

    • ANALYSIS COMPLETE NO VIRUS

    • ANALYSIS FAILED

    • ANALYSIS COMPLETE MALWARE DETECTED

    Threat Severity Score The threat score most recently associated with this file. This is a value from 0 to 100.
    File Type Identifiers The type of file. For example, PDF or MSEXE.
    File Size (bytes) The size of the file in bytes, if the event matched rules with File Type Control or File Inspection enabled.
    Archive File Name The name of the archive file involved with the activity, if the event matched rules with File Type Control or File Inspection enabled.
    Archive Extraction Depth The level (if any) at which the file was nested in an archive file.
    Archive SHA-256 Hash The checksum of the archive file, if the event matched rules with File Type Control or File Inspection enabled.

View Web Events in Activity Search Report

The Activity Search report provides a detailed view of the web events in your organization. For more information about the Activity Search report, see View the Activity Search Report.


Filter the Report by Web Requests

Before you begin

A minimum user role of Read-only. For more information, see Manage Accounts.

Procedure

  1. Navigate to Monitor > Reports > Activity Search.

  2. Choose a time frame to view the report. You can view the results for the last 24 hours (default), Yesterday, Last 7 Days, Last 30 Days, or a Custom range.

  3. From the drop-down menu at the top-right of the table, choose the Web option to filter the report for web events.


    Yesterday, Last 7 Days, Last 30 Days, or a Custom range. From the drop-down menu at the top-right of the table, choose the Web option to filter the report for web events.
  4. Click the ellipsis (...) and choose the View Full Details option to view web event details in the side panel.


    The View Full Details interface.

    For more information, see View Activity Search Report Actions.


    The Activity Search interface.

    Web event details include the following fields that are also available as Activity Search report columns. For more information about these fields, see Customize the Activity Search Report.

    • Action

    • Time

    • Rule Name

    • Source

    • Rule Identity

    • Internal IP Address

    • External IP Address

    • Destination

    • Categories

    • Resource/Application

    • Application Category

    • Content Type

    • Request Method

    • Referrer

    • Status Code

    Web event details also include the following fields that do not appear as Activity Search report columns.

    Field Name Description
    Hostname Fully Qualified Domain Name (FQDN) of the machine or container from which the event originated.
    File Action (Remote Browser Isolation) Action taken on a file, such as Viewed, Original File Downloaded, Sanitized PDF File Downloaded.
    Total Size, in Bytes The number of bytes sent from the client for all the requests, including HTTP headers, for example, 234.
    User Agent The user agent string as captured by the proxy, for example, Mozilla 5.0 (X11; Linux x86_64; rv:12.0) Gecko 20100101 Firefox 21.0.
    SHA256 Hash This represents the SHA-256 hash of the response body.
    Egress IP Address The IP address is used by the proxy to communicate with the origin server. Dot notation is used for IPv4 and RFC 5952 is used for IPv6 , for example, 1.2.3.4, 2001:db8::1.
    Egress Data Center The data center that processed the request.
    YouTube Channels The YouTube channel name, such as @Cisco in the Cisco YouTube channel (https://www.youtube.com/@Cisco).
    YouTube Categories The set of YouTube categories, such as Education, Entertainment, Animation.

View Zero Trust Events in Activity Search Report

The Activity Search report includes the full details about the Zero Trust Access traffic events in your organization. For more information about the Activity Search report, see View the Activity Search Report.

Note
If you assign Block to a rule that is destine for a private application and there is an HTTPS “Get” request for a downloadable file, the rule blocks matching traffic and actions appropriately but the event appears in Activity Search twice: one entry as the action is “blocked” and one entry as the action is “allow”. Activity Search does not currently condense events that generate multiple entries and thusly increases the hit counter as “2”.

Procedure

Before you begin

A minimum user role of Read-only. For more information, see Manage Accounts.

Procedure

  1. Navigate to Monitor > Reports > Activity Search.

  2. Choose a time frame to view the report. You can view the results for the last 24 hours (default), Yesterday, Last 7 Days, Last 30 Days, or a Custom range.

  3. From the Requests menu, choose a request type or the default of All. Filters update to those that are relevant to the type of request chosen.

  4. For an item in the report, click on the ellipsis (...). Click View Full Details to display the details of the Zero Trust Access event.


Event Details

View the Zero Trust event details in the Activity Search report.

The Event Details interface.
Field Name Description
Connection Staus Indicates the result of the connection attempt, such as Success or Blocked.
Failure Reason/Block Reason If the connection was not successful, this field explains the reason for the failure. Block Reason is displayed for authorization events. Failure Reason is displayed for flow events.
Connection Method The type of connection method: ZTA Client-based or ZTA Browser-based.
Ingress Region The geographic region of the data center where Secure Access received the incoming connection request.
Data In The total amount of data received from the client during the connection session, displayed in megabytes (MB).
Data Out The total amount of data sent to the client during the connection session, displayed in megabytes (MB).
Time The timestamp indicating when the event occurred.

Access Details

View the Zero Trust access details in the Activity Search report.


The Zero Trust Activity Search Access Details Only interface.
Field Name Description
Identity The name and email of the user identified in the Zero Trust connection event.
Ingress Region The geographic region of the data center where Secure Access received the incoming traffic.
Resource/Application The name of the private application.
Zero Trust Access Profile The name of the Zero Trust Access Profile used in the event.
Trusted Network The trusted network identified in the connection, disconnection, or evaluation of a policy-triggered event.
Egress IP The IP address used when traffic exits a network or system to reach the destination outside of it.
Resource Connector Group The ID of the resource connector group that provides access to the private resource.
Tunnel Type The type of traffic supported by the network tunnel, which the endpoint established with the proxy. The transport protocol on the tunnel is either HTTP or HTTP3.
Transaction ID The unique ID associated with the Zero Trust connection request. Use the transaction ID to correlate and troubleshoot connection issues.

Block Details

View the Zero Trust block details in the Activity Search report.


The Zero Trust Activity Search Block Details interface.
Field Name Description
Block Reason Secure Access provides an explanation for blocking access to the private resource.
Associated Rule When access was blocked for not meeting access or posture requirements, Secure Access reports the closest matched policy rule that would have allowed access.
Associated Posture Profile The posture profile that is configured for the associated rule.

Endpoint Details

View the Zero Trust endpoint details in the Activity Search report.


The Zero Trust Activity Search Endpoint Details interface.
Field Name Description
Client Location The two-character country identifier.
Client Location IP The IPv4 or IPv6 address of the client. Supports both compressed and long-form IPv6 address formats.
OS The operating system of the client's device.
Endpoint Security Agent The name of the endpoint security agent.
Disk Encryption Indicates if the client's device has disk encryption.
Firewall Indicates if the client environment has a firewall enabled.
System Password Indicates if the client has a system password enabled.
Endpoint Application The name of the endpoint application, which initiated the connection.
Application Signature The SHA256 signature of the endpoint application process.
Endpoint Username The username that is associated with the endpoint application process.

View AI Semantic Inspection Events in Activity Search Report

The Activity Search report provides a detailed view of the Model Context Protocol (MCP) communications on the MCP servers observed by Secure Access for the organization.


Filter the Report by Semantic Inspection for MCP Servers

Filter the Activity Search report for Model Context Protocol (MCP) messages on the MCP servers observed by Secure Access.

Before you begin

  • A minimum user role of Read-only in Secure Access.

Procedure

  1. Navigate to Monitor > Reports > Activity Search.

  2. Choose a time frame to view the report. You can view the results for the Last 24 hours, Yesterday, Last 7 Days, Last 30 Days, or a Custom range. The default time range is Last 24 hours.

    The Mcp Agents Timerange Activity Search interface.
  3. Navigate to Event Type, and then click Semantic Inspection.

    The Semantic Inspection Event Type 10 10 interface.

    Secure Access displays the events of the detected MCP messages on the MCP servers.

    1. Navigate to an item in the table for the Activity Search report, click the ellipsis (...), and then choose View Full Details.

      In the side panel, Secure Access displays the details of the MCP event on the MCP server. For information about the web events in the Activity Search report, see Filter the Report by Web Requests

    2. Navigate to Model Context Protocol.

      Secure Access displays the details about the MCP server and the verdict assigned to the MCP messages.

      • Type—The type of action performed by the MCP server, for example tools/call.

      • Reason—The reason for the verdict assigned by Secure Access for the action on the MCP server.

      The Mcp Event Details interface.

View Activity Search Report Actions

To learn more about the results of your activity search, click the View Actions icon for a result and choose an item from the menu.


See Full Details

Before you begin

A minimum user role of Read-only. For more information, see Manage Accounts.

Procedure

For each entry listed, from the View Actions icon, choose View Full Details.

What to do next


The View Full Details interface.

The details of each activity result are displayed. The details listed depend on the event type.


The details of each activity result are displayed. The details listed depend on the event type.

View Isolated Event Details

Before you begin

A minimum user role of Read-only. For more information, see Manage Accounts.

Procedure

  1. Navigate to Monitor > Activity Search.

  2. Select Isolated in the filter pane.

    The Isolated events appear.

    Image displaying the Activity Search window with Isolated filter applied
  3. Click the View Actions icon (three dots) for any event to view a menu of options and then click View Full Details.

    Image displaying the View Actions menu
  4. The Event Details window displays information depending on the Event Type:

    • Action — Indicates the action taken on the event. In this case, the traffic was allowed but routed through an isolated (Remote Browser Isolation) environment.

    • Time — The timestamp when the event occurred.

    • Rule Name — The name of the rule that was triggered for this event.

    • Tenant List — Lists the tenants associated with the event.

    • Tenant ID — The ID of tenants associated with the event

    • Source — The IP address from which the request originated.

    • RBI Profile Name — The name of the Remote Browser Isolation (RBI) profile applied to this session.

    • Rule Identity — The identity (IP) of the triggered rule.

    • Internal IP Address — The internal (private) IP address of the source.

    • External IP Address — The external (public) IP address of the source.

    • Destination — The full URL the user attempted to access.

    • Hostname — The hostname/domain of the destination website.

    • Categories — The content categories assigned to the destination.

    • Dispute Categorization — An option to dispute or challenge the assigned category.

    • Resource/Application — The specific application or resource being accessed.

    • Application Category — The broader category under which the application falls.

    • YouTube Channels — Specific YouTube channel information (if applicable).

    • YouTube Categories — YouTube content category (if applicable).

    • Content Type — Specifies the format and character encoding of the content returned by the destination.

    • File Action (Remote Browser Isolation) — Indicates any file-level action taken during the RBI session.

    • Total Size in Bytes — The total size of the data transferred during this event.

    • Request Method — The HTTP method used for the request.

    • Referer — The referring URL that led to this request.

    • Status Code — The HTTP response status code (200 indicates a successful request).

    • User Agent — Information about the browser and operating system used to make the request.

    • Egress IP Address — The IP address used to exit the network toward the destination.

    • Egress Data Center — The data center from which the request exited.

    Image displaying the Event Details window.

Filter Views

Where applicable, certain results can be filtered by the following:

  • Application
  • Destination
  • URL
  • Source
  • External IP
Note
  • The URL filter applies only to proxy or web requests, whereas the domain filter applies to both DNS and proxy or web requests.
  • The Destination column displays either a URL (for example, https://example.com/profile/log/info) or a domain (for example, www.google.com)
  • To filter URLs in the Destination column, use the URL filter. To filter domains in the Destination column, use the domain filter.
    The Action Menu Filters interface.

Schedule an Activity Search Report

You can schedule a report to be emailed to you at regular intervals. Your emailed report is a table showing an HTML version of the report and an attached CSV file containing the entire data set. Also included in your email is a link to a live version of the same report. For more about scheduled reports, see Schedule a Report.

When scheduling a new report for Activity Search, any current filters selected apply.


The Schedule a Report interface.

In addition to using the filters to narrow the activity results in the Activity Search report, the Search and Advanced Search features provide further filtering of event details. For example, you can search for events with specific domains but exclude sub-domains you are not interested in.

Prerequisites

A minimum user role of Read-only. For more information, see Manage Accounts.


Search the report for domains, identities, or URLs. To search and filter the report by more options, such as threat type or file name, use Advanced Search.


The Activity Search interface.

Wildcards

Wildcards, such as '*', are special symbols that allow you to perform flexible searches when you are unsure of the exact spelling or full string of a specific term. By using these characters, you can broaden your search results to include multiple variations of a term simultaneously.

Wildcards available for some fields (Domains, URLs, and File names) allow you to search for all variations within that field. For example, using *.gif in File Name will search for all files that are .gifs.


Domains

Domains can be searched in the search bar or advanced search with the wildcard * to include or exclude subdomains. For example, example.com will search the top-level parent domain of Example, *.example.com will search for only the subdomains of Example, and *example.com will search for both the parent and subdomains of Example.

You can use wildcards to search by top-level domain. For example, *.example will search for all top-level domains that end in .example.


The Example Search interface.

URLs

The wildcard * can be used in any part of the URL path to search for URLs containing certain terms. For example, example* will search for URLs containing "example".


The Activity Search interface.

File Names

File names can use the wildcard * to search for file types, in Advanced Search only. For example, *.gif will search for all files that are .gifs.


The Activity Search interface.

Procedure

  1. In the search bar, click Advanced to open the Advanced Search window.

  2. Add search parameters and click Apply.

    Search Parameter Description
    Identity Include or exclude identity sources in search results. Secure Access opens a menu listing sources as soon as you begin typing.
    Domain Include or exclude one or more domains in search results. Wildcards are supported. When you add a domain, a new field appears so that you can add or exclude another domain.
    SHA256 Search by the hash function.
    URL Include or exclude specific URLs in search results. Wildcards are supported.
    IP Address Include or exclude events associated with specific IPv4 or IPv6 addresses on your network (either internal or public egress IP address). Supports both compressed and long-form IPv6 address formats. This does not provide the capability to search for destination IP addresses.
    IP Address Port Search by a firewall port number, port range (e.g. 81-222), or port group (e.g. 81,8080,222).
    Subnet Search for events based on IPv4 or IPv6 subnets using CIDR notation. Supports including or excluding multiple subnets.
    Threat Search by threats.
    Threat Type Search by threat type. For more information, see Threat Category Descriptions .
    AI Supply Chain Category Search by the categories Prohibited Suppliers, Code Execution, or Copyleft License. For more information, see Customize the Activity Search Report.
    AI Model Name Search by AI model name. Wildcards are supported.
    Block Reason Include or exclude reasons for a blocked request. Wildcards are supported.
    Transaction ID Include or exclude transaction IDs. Wildcards are supported.
    Public Application Search by any public application.
    Application Group Search by any application group available in the drop-down.
    File Name Search by the name of a file. Wildcards are supported.
    IPS Signature List Names Search by default and custom IPS Signature List Names. For more information, see Manage IPS .
    IPS Signatures Search by up to twenty IPS signatures. For more information, see Manage IPS Profiles .
    OS Type Search by operating system from which the request originated.
    Location Search by the location from which the request originated.
    Egress IP Type Search by the egress IPv4 or IPv6 addresses: shared or reserved. Supports both compressed and long-form IPv6 address formats.
    Egress Data Center Search by the egress data center location from which activity originated.

Inline Column Filtering

You can now quickly filter results directly from columns in the Activity Search dashboard. You can use inline filtering on the following columns by hovering over the column header to access the Search or Exclude option:

  • Rule Name

  • Application

  • Protocol

  • Port

  • Destination Country

  • Browser OS

  • Location

  • Zero Trust Profile

To use this feature, hover over the header of one of the supported column. You will see pop-up options to Search or Exclude results based on the value in that column. This enhancement makes it easier to focus on relevant data directly from the report table, without opening Advanced Search.