Web Push Security Events

Secure Access KeyTypeDescription
specversionstringThe version of the Push Security Event schema.
typestringThe type of the security event.
sourcestringThe unique label that describes the source of the security event.
orgidintegerThe unique identifier of the organization.
integrationidstringThe unique identifier of the integration.
idstringThe unique identifier for the push security event.
timestringThe date and time when the system sent the event. The system formats the timestamp in the ISO 8601 format.
datacontenttypestringThe type of the content in the push security event.
dataobjectThe properties of the data for the push security events.

data

Secure Access KeyTypeDescription
eventsarrayThe list of push security event messages.

data.events

Secure Access KeyOCSF KeyTypeDescription
activity_idnumberThe unique identifier of the activity that triggered the security event.
category_uidintegerThe unique identifier of the security event category.
cisco_ai_supply_chainobjectThe properties of the AI supply chain models.
cisco_event_idEvent IDstringThe unique identifier of the security event.
cisco_event_typestringThe type of the security event.
cisco_organization_idOrganization IDnumberThe unique identifier of the organization.
cisco_mcparrayThe list of the MCP servers.
cisco_originobjectThe properties of the origin.
cisco_other_originsarrayThe list of the origins.
cisco_swg_metadataobjectThe properties of the Secure Web Gateway (SWG) metadata.
cisco_swg_verdictobjectThe properties of the verdict determined by the antivirus and malware engines and the Secure Web Gateway (SWG).
class_uidnumberThe unique identifier of the class.
dst_endpointobjectThe IPv4 or IPv6 address of the origin server.
fileobjectThe properties of the file.
http_requestobjectThe properties of the HTTP request.
http_responseobjectThe properties of the HTTP response.
metadataobjectThe properties of the metadata for the web events.
policyobjectThe properties of the access rules in the Access policy.
proxy_endpointobjectThe properties of the endpoint used by the proxy to communicate with the origin server.
severity_idnumberThe unique identifier of the severity.
src_endpointobjectThe properties of the client endpoint.
timeTimestringThe date and time when the system recorded the security event. The system formats the timestamp in milliseconds since the Unix Epoch.
type_uidintegerThe unique identifier of the type for the security event.

data.events.cisco_ai_supply_chain

Secure Access KeyOCSF KeyTypeDescription
model_nameModel NamestringThe name of the AI model.
scr_categoriesSource Categoriesarray(string)The properties of the source category.

data.events.cisco_mcp

Secure Access KeyOCSF KeyTypeDescription
agent_idAgent IDstringThe identifier of the MCP agent.
mcp_framesarrayThe list of the MCP servers.

data.events.cisco_mcp.mcp_frames

Secure Access KeyOCSF KeyTypeDescription
directionstringThe direction of the frame.
frame_idstringA unique identifier for the frame that is used to correlate the request and response.
frame_typestringThe type of the frame.
verdictstringThe verdict returned by Cisco semantic inspection engine.
reasonstringThe reason for the verdict returned by the Cisco semantic inspection engine.

data.events.cisco_origin

Secure Access KeyOCSF KeyTypeDescription
idOrigin IDintegerThe unique identifier of the endpoint.
typeOrigin TypestringThe type of the endpoint, for example: Networks or AD Computers.

data.events.cisco_other_origins

Secure Access KeyOCSF KeyTypeDescription
idIDnumberThe unique identifier of the endpoint.
typenumberThe type of the endpoint. Use 1 for Networks and 5 for AD Computers.

data.events.cisco_swg_metadata

Secure Access KeyOCSF KeyTypeDescription
connection_idstringThe ID of the connection. Use the identifier to correlate this connection with other services.
forwarding_methodForwarding MethodstringThe type of method used to forward the identity of the client to the proxy.
https_query_paramsQuery ParamsstringThe query parameters in the HTTP message.
internal_client_ipInternal Client IPstringThe internal IP address of the client connecting to the proxy through a forwarding method such as a Virtual Appliance or SAML.
is_decryptedDecryptedbooleanSpecifies whether the HTTP message is decrypted.
is_reserved_ipIs reserved IPbooleanSpecifies whether the IP address is reserved for the organization.
response_sha256Response sha256stringThe SHA-256 hash of the response body.
traffic_sourceTraffic SourcenumberThe source of the web traffic. The possible values are 0 - Unknown, 1 - VPN, 2 – ZTNA, 3 - Network Tunnel, 4 - Network, 5 - SWG Roaming.

data.events.cisco_swg_verdict

Secure Access KeyOCSF KeyTypeDescription
actionActionstringThe action (allow or block) in the access rule associated with the web traffic.
amp_dispositionDispostionstringA file's disposition is a categorization from the AMP cloud that determines what actions are taken on the file download.
amp_malware_nameMalware NamestringThe name of the malware detected by AMP.
amp_scoreScorenumberThe risk score associated with the file or object in the web traffic.
av_enginesNamearrayThe list of the properties for the antivirus (AV) engines.
avcApplication IDsobjectThe properties of the application visibility and control.
blocked_categoriesarray(string)The category that matches the request and the block action in the access rules.
blocked_destination_countriesBlocked Destination Countriesarray(string)The ISO-3166 ID of the country associated with the destination IPs and the block action in the access rules.
categoriesCategoriesarray(string)The category that matches the request.
detected_response_file_typeDetected Response File TypestringThe type of file in the detected response by the file type control that resulted in a block based on various signals.
dlp_statusDLP StatusstringThe status that was returned from the inline DLP scanning.
http_errorsTypearrayThe list of HTTP errors.
remote_browser_isolationIsolated StateobjectThe properties of the Remote Browser Isolation (RBI) session.

data.events.cisco_swg_verdict.av_engines

Secure Access KeyOCSF KeyTypeDescription
nameNamestringThe name of the AV Engine used to scan the files. For example: kaspersky, bitdefender.
data_versionData VersionstringThe version of the data package, which includes the timestamp of the signatures.
engine_versionEngine VersionstringThe version of the AV engine used to scan the files.
threatsThreatsarray(string)The name of the threat returned by the AV engine.

data.events.cisco_swg_verdict.avc

Secure Access KeyOCSF KeyTypeDescription
allowed_application_idsAllowed Application IDsarray(string)The identifier of the application that matches the request and the allow action in the access rules.
application_entity_categoryApplication Entity CategorystringThe category attribute associated with the application entity.
application_entity_nameApplication Entity NamestringThe name of the entity or user within the application. In the case for YouTube, this is a channel name which is also a string identifying the actual channel name. For example, '@CiscoSystems' in the Cisco YouTube channel (https://www.youtube.com/@CiscoSystems).
application_idsApplication IDsarray(string)The identifier of the web applications.
blocked_application_idsBlocked Application IDsarray(string)The identifier of the application that matches the request and the block action in the access rules.

data.events.cisco_swg_verdict.http_errors

Secure Access KeyOCSF KeyTypeDescription
typeTypestringThe label for the type of HTTP error.
codeCodestringThe code of the HTTP error.
reasonReasonstringThe reason for the HTTP error.
attributesAttributesarray(string)The attribute of the HTTP error.

data.events.cisco_swg_verdict.remote_browser_isolation

Secure Access KeyOCSF KeyTypeDescription
file_actionFile ActionstringThe type of action taken on the file.
isolated_stateIsolated StatestringThe status of the remote browser isolation (RBI) session for the web request.

data.events.dst_endpoint

Secure Access KeyOCSF KeyTypeDescription
ipDestination IPstringThe IPv4 or IPv6 address of the origin server (destination). For example: 1.2.3.4', '2001:db8::1.

data.events.file

Secure Access KeyOCSF KeyTypeDescription
nameFile NamestringThe name of the file listed in the response as the Content-Disposition: attachment.
type_idnumberThe identifier of the type of file listed in the response as the Content-Disposition: attachment.

data.events.http_request

Secure Access KeyOCSF KeyTypeDescription
http_methodRequest MethodstringThe HTTP request method, for example: GET, POST, HEAD, DELETE, PATCH.
lengthTotal Size in bytesnumberThe total number of bytes sent from the client for the full request. The number of bytes is set in the Content-Length heading in the HTTP request.
referrerReferrerstringThe address of the previous web page where a link to the currently requested page was followed as captured by the proxy. For example: 'http://www.example.com/index.html?a=b&c=a%20word').
urlRequest URLobjectThe properties of the Uniform Resource Locator (URL) defined by RFC 1738.
user_agentUser AgentstringThe name of the user agent as captured by the proxy. For example: 'Mozilla/5.0 (X11; Linux x86_64; rv:12.0) Gecko/20100101 Firefox/21.0').

data.events.http_request.url

Secure Access KeyOCSF KeyTypeDescription
url_stringRequest URLstringThe Uniform Resource Locator (URL) of the web resource requested as defined by RFC 1738. For example: 'http://www.example.com/index.html?a=b&c=a%20word').

data.events.http_response

Secure Access KeyOCSF KeyTypeDescription
body_lengthBody Size in bytesnumberThe length of the HTTP message body.
codeResponse Status CodenumberThe HTTP status code for the HTTP message.
content_typeResponse Content TypestringThe value of the Content-Type header in the HTTP message.
lengthTotal Size in bytesnumberThe value of the Content-Length header in the HTTP message.

data.events.metadata

Secure Access KeyOCSF KeyTypeDescription
correlation_idTransaction IDstringThe identifier of the transaction used for the correlation with the UUID of another service.
productobjectThe properties of the product.
versionstringThe version of the product.

data.events.metadata.product

Secure Access KeyOCSF KeyTypeDescription
namestringThe name of the product.

data.events.policy

Secure Access KeyOCSF KeyTypeDescription
dataobjectThe properties of the policy data.
uidRule IDstringThe unique identifier of the access rule that applies to the web traffic in the Access policy.

data.events.policy.data

Secure Access KeyOCSF KeyTypeDescription
destination_list_idsDestination List IDsarray(string)The ID of the destination list selected on the access rules in the Access policy and apply to the web traffic.
security_overriddenSecurity OverriddenbooleanSpecifies whether the system has overriden security filtering access rules in the Access policy and not applied during rule enforcement.
tenant_idTenant IDstringThe ID of the tenant that the system extracted from the HTTP request.
tenant_profile_nameTenant Profile NamestringThe name of the tenant control profile configured in the access rule in the Access policy. The traffic matches the tenant control profile for the matcheing tenant ID.
time_based_ruleTime Based RulebooleanSpecifies whether a schedule is enabled on the access rule that applies to the web traffic in the Access policy.

data.events.proxy_endpoint

Secure Access KeyOCSF KeyTypeDescription
ipEgress IPstringThe IPv4 or IPv6 address used by the proxy to communicate with the origin server.

data.events.src_endpoint

Secure Access KeyOCSF KeyTypeDescription
ipExternal Client IPstringThe IPv4 or IPv6 address of a client as seen by the proxy. For example: 1.2.3.4, 2001:db8::1.