cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1341
Views
0
Helpful
1
Replies

WSA access log schema

flyerhawk
Level 1
Level 1

We are having problems trying to identify why the WSA is blocking Slack calls.  We are seeing the following error...

 

SyslogAccess: Info: 1510782070.590 0 10.129.X.X TCP_DENIED/407 0 CONNECT tunnel://slack-calls-0f839364977b8qwdsc8.slack-core.com:443/ - NONE/- - OTHER-NONE-DefaultGroup-NONE-NONE-NONE-NONE <-,-,-,"-",-,-,-,-,"-",-,-,-,"-",-,-,"-","-",-,-,-,-,"-","-","-","-","-","-",0.00,0,-,"-","-",-,"-",-,-,"-","-",-,-,"-"> - NONE, "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) AtomShell/2.8.2 Chrome/56.0.2924.87 AtomShell/1.6.15 Safari/537.36 Slack_SSB/2.8.2 Slack_SSB/2.8.2 Slack_SSB/2.8.2"
N

 

My first question is whether anyone knows the definitions of the fields in the WSA log format?  

 

My 2nd question is what is causing this to be denied?    This site is explicitly allowed and works for other users.     

 

 

1 Reply 1

flyerhawk
Level 1
Level 1

I do realize it is a 407 error but the rule allows unauthenticated users to connect.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: