The Content inspection activity log indicates that data was sent to the Cloud Detection Service CDS and that data violated the policy. It is a redundant log to Policy Violation (Policy Alert filter). The logs can be filtered in both CASB investigate and the securlet Activities tab.
The Content Inspection log has been deprecated from o365 and GSuite securlet. The CI will be deprecated for all securlets later in 2025.