i try to clarify using an example. Having an appctrl rule for facebook (block + log) in place... httpproxy + ssl scanning + application control enabled => logging HTTP and HTTPS traffic to http.log httpproxy + no ssl scanning + application control enabled => logging HTTP to http.log -- HTTPS and other protocols to afc.log application control enabled => HTTP HTTPS and other protocols to afc.log
This example makes the assumption that the client uses the httpproxy (allowed network) if it is enabled. If the httpproxy is configured not to serve for the client, its traffic will be logged in afc.log
@utm_kid: hope that helps, if not send me the credentials to your box and the client behind it.