Reports
Use Reports to prove what SafeSquid allowed, blocked, inspected, bypassed, or forwarded. A policy without reportable evidence cannot support audit, incident response, or executive risk decisions. The Application Eco-system source identifies SIEM log forwarding over UDP for real-time access, extended, and native logs. Treat Reports as the console entry point for that evidence flow.Evidence to review
- access outcomes by user, group, source, destination, and policy
- blocked malware, phishing, category, and application events
- bypass or exception activity
- configuration and privileged-access changes
- SIEM forwarding status for real-time investigation
Verification
After a policy change, trigger a controlled request and confirm:- The expected allow or block decision appears in Reports.
- The event includes enough identity and destination context for investigation.
- The same event reaches the SIEM when forwarding is configured.
Next steps
- Use Reporting Service for deployment patterns and troubleshooting.
- Use Configure to adjust the policy that generated the report.

