Hub
Web & Access

Cisco Secure Web Appliance Access Log

Cisco Secure Web Appliance (AsyncOS 15.2) standard Squid-style access log entries from one appliance serving 40 office clients: page browsing, cache hits, software downloads from mirrors, and URL-category and web-reputation blocks, as the native line in event.original with an inferred ECS mapping. About 29,200 entries a day follow a working-day curve in UTC. Recurring episodes show a client denied a package on a blocked file-sharing site that then downloads the same path from an allowed mirror.

Quick Start

uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
  --path generators/proxy-cisco-secure-web-appliance/generator.yml \
  --id swa \
  --live-mode true

Event Types

Event IDDescriptionFrequencyCategory
TCP_MISS/200 DEFAULT_CASEPage, asset or POST fetched from the origin server57.7% of recordsweb
TCP_HIT/200Served from disk cache9.1% of recordsweb
TCP_IMS_HIT/304If-Modified-Since answered from cache9.0% of recordsweb
TCP_DENIED/403 BLOCK_WEBCATBlocked URL category (games, gambling, streaming, filter avoidance, file sharing)6.7% of recordsweb
TCP_MEM_HIT/200Served from memory cache5.9% of recordsweb
TCP_REFRESH_HIT/200Revalidated cached object5.0% of recordsweb
TCP_CLIENT_REFRESH_MISS/200Client sent Pragma: no-cache2.7% of recordsweb
software downloadPackage fetched from an allowed mirror (TCP_MISS/200, about 5% TCP_CLIENT_REFRESH_MISS/200) with AMP file name and SHA-2562.5% of recordsweb, file
NONE/503, NONE/504Upstream DNS failure or gateway timeout0.9% of recordsweb
TCP_DENIED/403 BLOCK_WBRSLow web-reputation score0.4% of recordsweb

Realism Features

  • About 29,200 entries a day, varying by about 3% from day to day: 350 an hour at 22:00-05:00 UTC, 750 at 05:00-06:00 and 19:00-22:00, 1,250 at 06:00-08:00 and 17:00-19:00, 1,750 at 08:00-09:00 and 15:00-17:00, and 2,250 at 09:00-15:00. Every day has the same working-day curve, with no weekend dip.
  • One appliance serves 40 office clients browsing 10 allowed sites. Each client has its own working hours, starting between 04:00 and 11:00 UTC and lasting 7 to 10.5 hours, shifted by a random amount each day (standard deviation about 35 minutes), with about one day in ten off; outside them it stays at about an eighth of its daytime activity, and at 45% in the four hours after. Client activity weights are skewed but bounded (the busiest client carries about 8% of the entries), and the same clients are the busy ones on every run for a given subnet.
  • Requests of one page view are spread over consecutive entries: embedded objects follow their page after a median of 1.6 s in office hours (90th percentile 5.5 s) and 7.5 s at night (90th percentile 26 s), where a real browser fetches them within about a second. Traffic shares and timings are synthetic, not measured appliance data.
  • Every episode element also occurs in ordinary traffic of both modes: all clients, sharing sites, mirrors and packages, and every episode client with every package; repeated denials of one package by a client within minutes, a single denial followed by the same package from a mirror, denials followed by a different package, and plain mirror downloads. In ordinary traffic a client denied a package twice or more in the preceding 30 minutes does not download that same package and fetches a different package from the mirror instead. With anomaly_mode true, repeated denials of one package by one client are about one per episode more frequent.
  • Episode starts follow the overall hour curve, which keeps some weight in the evening, and each later start is only pulled towards busier hours within its own window, so an evening start can repeat for several days.
  • The native line follows the AsyncOS 15.2 standard access log with the six-component ACL decision tag (the example line's extra trailing -NONE is not reproduced) and scanning-verdict positions 1-39 (URL category through AMP SHA-256). Archive-scan, Web Tap and YouTube positions 40-44 are omitted, and the exact verdict length may differ by release and enabled features.
  • URL categories are written quoted as the guide states for AsyncOS 11.8 and later, although its example lines show them unquoted. No complete raw AsyncOS 15.2 line of a clean transaction was available as a reference: Webroot, McAfee, Sophos, DLP and AVC positions are hyphens or "Unknown" as in the guide examples, and WBRS scores, bandwidth and AMP verdicts are synthetic within the documented value ranges.
  • Only plain HTTP GET/POST through an explicit proxy is modeled: no HTTPS CONNECT tunnels, decryption decisions, authenticated usernames, W3C logs or syslog wrapping. No Elastic integration exists for this source, so the ECS mapping is inferred.

Sample Output

{
  "@timestamp": "2026-09-01T12:31:57.557+00:00",
  "cisco": {
    "swa": {
      "acl_decision_tag": "DEFAULT_CASE_11-Staff-Corp_Identity-DefaultGroup-NONE-NONE-DefaultRouting",
      "elapsed_ms": 1381,
      "hierarchy": "DIRECT/updates.example.org",
      "mime_type": "application/zip",
      "policy_group": "Staff",
      "result_code": "TCP_MISS",
      "scan_verdict": "\u003c\"IW_swup\",4.7,-,\"-\",-,-,-,-,\"-\",-,-,-,\"-\",-,-,\"-\",\"-\",-,-,\"IW_swup\",-,\"-\",\"-\",\"-\",\"Unknown\",\"Unknown\",\"-\",\"-\",54062.07,0,-,\"-\",\"-\",0,\"-\",-,0,\"netscan-3.5.zip\",\"5cf61ec035254ada6e53e0ec3b2c5c418646181bff880556d85f1dcb81ee0dfb\"\u003e",
      "url_category": "IW_swup",
      "wbrs_score": "4.7"
    }
  },
  "destination": {
    "domain": "updates.example.org"
  },
  "ecs": {
    "version": "8.17.0"
  },
  "event": {
    "action": "tcp_miss",
    "category": [
      "web",
      "network"
    ],
    "dataset": "cisco_swa.access",
    "duration": 1381000000,
    "kind": "event",
    "original": "1788265917.557 1381 10.20.40.17 TCP_MISS/200 9332465 GET http://updates.example.org/pub/netscan/netscan-3.5.zip - DIRECT/updates.example.org application/zip DEFAULT_CASE_11-Staff-Corp_Identity-DefaultGroup-NONE-NONE-DefaultRouting \u003c\"IW_swup\",4.7,-,\"-\",-,-,-,-,\"-\",-,-,-,\"-\",-,-,\"-\",\"-\",-,-,\"IW_swup\",-,\"-\",\"-\",\"-\",\"Unknown\",\"Unknown\",\"-\",\"-\",54062.07,0,-,\"-\",\"-\",0,\"-\",-,0,\"netscan-3.5.zip\",\"5cf61ec035254ada6e53e0ec3b2c5c418646181bff880556d85f1dcb81ee0dfb\"\u003e -",
    "outcome": "success",
    "type": [
      "allowed",
      "connection"
    ]
  },
  "file": {
    "hash": {
      "sha256": "5cf61ec035254ada6e53e0ec3b2c5c418646181bff880556d85f1dcb81ee0dfb"
    },
    "name": "netscan-3.5.zip"
  },
  "host": {
    "name": "swa-01.example.test"
  },
  "http": {
    "request": {
      "method": "GET"
    },
    "response": {
      "bytes": 9332465,
      "mime_type": "application/zip",
      "status_code": 200
    }
  },
  "network": {
    "protocol": "http"
  },
  "observer": {
    "hostname": "swa-01.example.test",
    "product": "Secure Web Appliance",
    "type": "proxy",
    "vendor": "Cisco"
  },
  "related": {
    "hash": [
      "5cf61ec035254ada6e53e0ec3b2c5c418646181bff880556d85f1dcb81ee0dfb"
    ],
    "hosts": [
      "updates.example.org"
    ],
    "ip": [
      "10.20.40.17"
    ]
  },
  "source": {
    "ip": "10.20.40.17"
  },
  "url": {
    "domain": "updates.example.org",
    "full": "http://updates.example.org/pub/netscan/netscan-3.5.zip",
    "original": "http://updates.example.org/pub/netscan/netscan-3.5.zip",
    "path": "/pub/netscan/netscan-3.5.zip",
    "scheme": "http"
  }
}

Parameters

ParameterDefaultDescription
anomaly_modetrueAdd periodic anomaly episodes to background; false produces background only
anomaly_interval_hours24Source time between episodes, counted from the actual start of the previous one, 1 to 8,760
host_nameswa-01.example.testAppliance hostname
client_prefix10.20.40.Client subnet prefix
client_first11First client host number
client_count40Number of clients, at least 4
access_policies[Staff, Engineering]Two Access Policy group names in the ACL decision tag
identity_policyCorp_IdentityIdentification Profile name in the ACL decision tag
sites10 allowed sitesBrowsed domains with URL category abbreviation and pages
blocked_sites4 sitesDomains blocked by URL category
sharing_sites3 sitesBlocked file-sharing domains used for package downloads
mirrors3 sitesAllowed download mirrors
low_reputation_domains3 domainsDomains blocked by web reputation
packages10 pathsSoftware package paths hosted on sharing sites and mirrors
assets8 pathsEmbedded page objects

Related Generators