For Web Security Gateway Anywhere, Hybrid/Cloud activity logs shall be reported via SYSLOG via the SIEM integration service, as for any internal traffic (using on-premise appliances).
This is not working today (as only logs from internal appliances are sent to the multiplexer), and I personally think this is a bug (cf: "Topic 65010 | SIEM | Web Security Solutions | Updated 22-Jul-2014" document). However I've been informed by the support team that this has not been designed to work like this, and this should be translated into a feature request.