When a ProxySG sends objects to be analysed by an ICAP server such as Content Analysis, the results of the analysis are added to the "rs-icap-status" field which can be viewed in the proxies access log.
Valid results include:
ICAP_NOT_SCANNED - the object was not scanned
ICAP_NO_MODIFICATION - the object was scanned but no malware was found
ICAP_REPLACED - the object was scanned and malware detected, ICAP replaced content with an exception page