Document toolboxDocument toolbox

Proxy

This group includes tags that start with the level proxy. These tags identify data generated by proxy servers.

Company Product / service Valid tags

-

Symantec ProxySG (formerly by Blue Coat Systems)

  • proxy.bluecoat.proxysg.bcreportermain_v1
  • proxy.bluecoat.proxysg.leef
  • proxy.bluecoat.proxysg.main

Check more info about these parsers

Forcepoint proxy access logs 

  • proxy.forcepoint.access

Check more info about these parsers

-

HAProxy HTTP log format

  • proxy.haproxy.http

-

Cisco Web Security (formerly IronPort) using AsyncOS
Access log in Squid format

  • proxy.ironport.access.squid
-

Microsoft Forefront Threat Management Gateway (formerly Microsoft ISA Server)

  • proxy.isaserver.access-w3c-ab

McAfee Web Gateway 

  • proxy.mcafee.webgw.access-ab
  • proxy.mcafee.webgw.default

-

Squid caching proxy 

  • proxy.squid.access-clf.<serverHostname>
  • proxy.squid.access-combined.<serverHostname>
  • proxy.squid.access-lt.<serverHostname>
  • proxy.squid.access-squid.<serverHostname>
  • proxy.squid.access-squid-mime.<serverHostname>
  • proxy.squid.cache.<serverHostname>

Check more info about these parsers

-

stunnel TLS Proxy

  • proxy.stunnel.stdout

-

Varnish HTTP Cache

  • proxy.varnish.access-combined
  • proxy.varnish.access-combined-xff

VMware 

  • network.vmware.airwatch.events

Zscaler Internet Access (ZIA) 

  • proxy.zscaler.zia.alert
  • proxy.zscaler.zia.dns
  • proxy.zscaler.zia.firewall
  • proxy.zscaler.zia.saas_collaboration
  • proxy.zscaler.zia.saas_crm
  • proxy.zscaler.zia.saas_email
  • proxy.zscaler.zia.saas_file
  • proxy.zscaler.zia.saas_itsm
  • proxy.zscaler.zia.saas_repository
  • proxy.zscaler.zia.tunnel
  • proxy.zscaler.zia.web

Check more info about these parsers

Zscaler Secure Web Gateway log fields


  • proxy.zscaler.access
  • proxy.zscaler.nss
  • proxy.zscaler.nss_web.cef
  • proxy.zscaler.nss_firewall.cef

Check more info about these parsers