When a ProxySG sends objects to be analysed by an ICAP server such as Content Analysis, the results of the analysis are added to the "rs-icap-status" field which can be viewed in the proxies access log.
Valid results include:
ICAP_NOT_SCANNED - the object was not scanned
ICAP_NO_MODIFICATION - the object was scanned but no malware was found
ICAP_REPLACED - the object was scanned and malware detected, ICAP replaced content with an exception page
ICAP_COMMUNICATION_ERROR - means a network error occurred while the ProxySG was attempting to communicate with the ProxyAV
ICAP_RESOURCE_OVERLOAD - When the objects do hit the resource overload , the information block for the HTTP object displays the message ICAP response type