Site → Security Events in the Mist UI is used to understand cases where traffic is intentionally blocked by security rules on the network.
This page records decisions made by security features such as firewall policies, threat prevention, and application controls. When an entry appears here, it means the device deliberately stopped the traffic because it matched a configured security rule.
Security Events are meant to explain security behavior, not network or WAN performance.
You should look at Site → Security Events when you experience situations such as:
These symptoms usually point to policy‑based blocking, not a network outage or WAN issue.
Use Site → Security Events to safely confirm whether traffic is being blocked intentionally by your network’s security configuration.
To view Security Events, navigate to:
Mist UI → Site → Security Events
In this section, you can clearly see:
This information helps you understand whether the observed behavior is expected and policy‑driven, rather than the result of a network or connectivity issue.
If traffic appears in Security Events, it indicates that the network is operating as designed, applying security rules to protect users and resources.
Security Events provide visibility and assurance, helping you confidently distinguish between security enforcement and other types of network issues.