Product guide

Table A-1 Blue Coat header formats (continued)
Format in extended log file Custom Content policy language Description
gmttime %t GMT date and time of the
user
request in [DD/MM/
YYYY:hh:mm:ss GMT] format
localtime %L Local date and time of the
user request in [DD/MMM/
YYYY:hh:mm:ss +nnnn]
format
rs(Content-Type) %c response.header.Content-Type Response header:
Content-type
sc-bodylength Number of bytes in the body
(excludes header ) sent from
appliance to client
sc-bytes %b Number of bytes sent from
appliance to client
sc-filter-category %f Content filtering category of
the request URL
sc-filter-result %W Content filtering result:
Denied, Proxied, or Observed
sc-headerlength Number of bytes in the
header sent from appliance
to client
sc-status %s Protocol status code from
appliance to client
time %y time.utc UTC (GMT) time in
HH:MM:SS format
timestamp %g Unix type time stamp
x-cache-user Relative user name of a
client authenticated to the
proxy (not fully
distinguished; same as
cs-username)
x-client-address IP address of the client
x-client-ip IP address of the client
x-cs-dns client.host The host name of the client
obtained through reverse
DNS
x-cs-http-method http.method HTTP request method used
from
client to appliance;
empty for non-HTTP
transactions
x-cs-user-authorization-name user.authorization_name User name used to authorize
a client authenticated to the
proxy
x-cs-user-credential-name user.credential_name User name entered by the
user to authenticate to the
proxy
x-cs-user-login-address user.login.address The IP address that the user
was authenticated in
A
Automatic-discover log formats
64
McAfee Content Security Reporter 1.0.0 Software Product Guide