LEEF key-value table
The following table contains a list of all the LEEF key names used to log data from these Forcepoint Email Security logs:
- Connection
- Message
- Policy
- Delivery
- Hybrid
- Audit
- Console
See Log format reference for details about the specific format of each log.
| LEEF Key Name | Key Value | Forcepoint Email Security Log |
|---|---|---|
| accountName | User that made a change | Audit |
| act | Policy action result Message delivery status |
Policy Delivery, Hybrid, Audit |
| cat | Antispam tool name | Policy |
| cc | Message header “Cc” | Message |
| connectionID | Connection ID | Connection, Message, Delivery |
| deliveryCode | Delivery status code | Delivery |
| deliveryCodeInfo | Delivery status information | Delivery |
| devTime | Time of event receipt (format is MMM dd yyyy HH:mm:ss) | Connection, Message, Policy, Delivery, Hybrid, Audit |
| deviceDirection |
Email direction: inbound/internal = 0 outbound = 1 |
Policy |
| deviceFacility | Policy name | Policy |
| deviceProcessName | Policy rule name | Policy |
| dst | Email destination IP address | Delivery |
| dvc | Email appliance IP address | Connection, Message, Policy, Delivery, Hybrid, Audit |
| element | Element on the page to which the change was applied | Audit |
| encryptedDelivery | Encryption type | Delivery |
| exceptionReason | Reason for exception (e.g., DLP policy, file sandbox, antivirus or antispam analysis) | Policy |
| fnameAndHash |
Message attachments in the format: <filename>|<filehash>|<triggered/clean/ malicious> |
Policy |
| from | Message header “from” | Message, Policy |
| hybridSpamScore | Email hybrid service spam score | Policy |
| identHostName | Email appliance fully qualified domain name (FQDN) | Connection, Message, Policy, Delivery, Hybrid |
| localSpamScore | On-premises email spam score | Policy |
| messageID | Message ID number | Message, Policy, Delivery, Hybrid |
| page | Page to which a change was made | Audit |
| reason | Connection status details Hybrid analysis result | Connection Hybrid |
| recipient | Destination (recipient) user name | Message, Policy, Delivery, Hybrid |
| replyTo | Message header “replyTo” | Policy |
| role | Role of the user that made a change | Audit |
| sender | Envelope sender | Message, Policy, Hybrid |
| spamScore | Email hybrid service spam score | Hybrid |
| spfResult | Relay control SPF check result | Connection |
| src | Email source IP address | Connection, Delivery, Hybrid, Audit |
| srcBytes | Inbound email size | Message, Policy, Hybrid |
| subject | Message subject | Message Policy, Hybrid |
| to | Message header “to” | Message |
| transport | Transport protocol | Connection, Delivery |
| trueSrc | True source IP address | Message, Policy |
| url |
Message embedded URLs in the format: <url>|<url category>|<triggered/not triggered> |
Policy |
| virus | Virus name | Policy |
| x-mailer | Email client | Message |