cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1978
Views
5
Helpful
2
Replies

Cloud Web Security reports for traffic older than a month is only showing blocked traffic in the logs.

chrischurch
Level 1
Level 1

I have a user who needs a report of their web browsing traffic for the past 6 months and when I ran a report it appears that traffic was only being allowed from just over month ago and all logs prior to that show just blocked traffic.

We know the user has been browsing the web fine during the last 6 months but why do I only see blocked traffic in the logs for traffic from over a month ago.

 

I had to run a similar report a few months ago for access to certain web sites and I saw allowed traffic in the logs but now when the same report is ran I no longer see logs showing the allowed traffic which I know was allowed when I first ran the report.

 

It seems to me that logs for allowed traffic older than month or two are being removed from the platform so only blocked logs are retained for older traffic logs.

 

 

 

1 Accepted Solution

Accepted Solutions

Hi,

Block requests (malware or policy) are retained for 1 year, however allowed data is only retained for 45 days. Reference here.

 

Certainly I know with Umbrella (which CWS is becoming) you can export logs to an AWS S3 bucket and retain data for longer and also export to a local SIEM. Not sure if that applies to existing CWS though.

 

HTH

View solution in original post

2 Replies 2

Hi,

Block requests (malware or policy) are retained for 1 year, however allowed data is only retained for 45 days. Reference here.

 

Certainly I know with Umbrella (which CWS is becoming) you can export logs to an AWS S3 bucket and retain data for longer and also export to a local SIEM. Not sure if that applies to existing CWS though.

 

HTH

Thanks for the prompt response.
Looking at the link you have provided it does mention that customers can retain the data to match the terms of their subscription which I need to check, as I mentioned I am sure I have seen logs older than 45 days in the past showing allowed traffic.

Chris.