Policy Log
<13>%<:%b %_2d %T> %<applianceHostName> vendor=Forcepoint
product="Email Security" version=%<version>event=Policy r
eason=%<reason> dvc=%<applianceIP>
dvchost=%<=applianceHostName> rt=%<timestamp>
messageId=%<messageId> suser="%<=sender>"
duser="%<=recipient>" from="%<=fromAddress>"
replyTo="%<=replyToAddress>" to="%<=to>" cc="%<=cc>"
in=%<messageSize> deviceDirection=%<direction>
deviceFacility=%<=policyName> deviceProcessName=%<=ruleName>
act=%<action> url="%<=urlDetail>" cat=%<=spamEngineName>
cs1=%<=virusName> fnameAndfileHash="%<=fileResult>"
exceptionReason=%<=exceptionReason>
hybridSpamScore=%<=hybridSpamScore>
localSpamScore=%<=localSpamScore> msg="%<=subject>"
trueSrc=%<tsip> x-mailer="%<=x_mailer>" %<\\n>