Policy log

<13>%<:%b %_2d %T> %<applianceHostName> 
CEF:0|Forcepoint|Email 
Security|%<version>|Policy|%<reason>|5| dvc=%<applianceIP> 
dvchost=%<=applianceHostName> rt=%<timestamp> 
messageId=%<messageId> suser=%<=sender> duser=%<=recipient> 
from=%<=fromAddress> replyTo=%<=replyToAddress> to=%<=to> 
cc=%<=cc> in=%<messageSize> deviceDirection=%<direction> 
deviceFacility=%<=policyName> deviceProcessName=%<=ruleName> 
act=%<action> url=%<=urlDetail> cat=%<=spamEngineName> 
cs1=%<=virusName> fnameAndfileHash=%<=fileResult> 
exceptionReason=%<=exceptionReason> 
hybridSpamScore=%<=hybridSpamScore> 
localSpamScore=%<=localSpamScore> msg=%<=subject> 
trueSrc=%<tsip> x-mailer=%<=x_mailer> %<\\n>