Policy log
<13>%<:%b %_2d %T> %<applianceHostName>
CEF:0|Forcepoint|Email
Security|%<version>|Policy|%<reason>|5| dvc=%<applianceIP>
dvchost=%<=applianceHostName> rt=%<timestamp>
messageId=%<messageId> suser=%<=sender> duser=%<=recipient>
from=%<=fromAddress> replyTo=%<=replyToAddress> to=%<=to>
cc=%<=cc> in=%<messageSize> deviceDirection=%<direction>
deviceFacility=%<=policyName> deviceProcessName=%<=ruleName>
act=%<action> url=%<=urlDetail> cat=%<=spamEngineName>
cs1=%<=virusName> fnameAndfileHash=%<=fileResult>
exceptionReason=%<=exceptionReason>
hybridSpamScore=%<=hybridSpamScore>
localSpamScore=%<=localSpamScore> msg=%<=subject>
trueSrc=%<tsip> x-mailer=%<=x_mailer> %<\\n>