LEEF key-value table

The following table contains a list of all the LEEF key names used to log data from these Forcepoint Email Security logs:

  • Connection
  • Message
  • Policy
  • Delivery
  • Hybrid
  • Audit
  • Console

See Log format reference for details about the specific format of each log.

LEEF Key Name Key Value Forcepoint Email Security Log
accountName User that made a change Audit
act Policy action result Message delivery status

Policy

Delivery, Hybrid, Audit

cat Antispam tool name Policy
cc Message header “Cc” Message
connectionID Connection ID Connection, Message, Delivery
deliveryCode Delivery status code Delivery
deliveryCodeInfo Delivery status information Delivery
devTime Time of event receipt (format is MMM dd yyyy HH:mm:ss) Connection, Message, Policy, Delivery, Hybrid, Audit
deviceDirection

Email direction:

inbound/internal = 0 outbound = 1

Policy
deviceFacility Policy name Policy
deviceProcessName Policy rule name Policy
dst Email destination IP address Delivery
dvc Email appliance IP address Connection, Message, Policy, Delivery, Hybrid, Audit
element Element on the page to which the change was applied Audit
encryptedDelivery Encryption type Delivery
exceptionReason Reason for exception (e.g., DLP policy, file sandbox, antivirus or antispam analysis) Policy
fnameAndHash

Message attachments in the format:

<filename>|<filehash>|<triggered/clean/ malicious>

Policy
from Message header “from” Message, Policy
hybridSpamScore Email hybrid service spam score Policy
identHostName Email appliance fully qualified domain name (FQDN) Connection, Message, Policy, Delivery, Hybrid
localSpamScore On-premises email spam score Policy
messageID Message ID number Message, Policy, Delivery, Hybrid
page Page to which a change was made Audit
reason Connection status details Hybrid analysis result Connection Hybrid
recipient Destination (recipient) user name Message, Policy, Delivery, Hybrid
replyTo Message header “replyTo” Policy
role Role of the user that made a change Audit
sender Envelope sender Message, Policy, Hybrid
spamScore Email hybrid service spam score Hybrid
spfResult Relay control SPF check result Connection
src Email source IP address Connection, Delivery, Hybrid, Audit
srcBytes Inbound email size Message, Policy, Hybrid
subject Message subject Message Policy, Hybrid
to Message header “to” Message
transport Transport protocol Connection, Delivery
trueSrc True source IP address Message, Policy
url

Message embedded URLs in the format:

<url>|<url category>|<triggered/not triggered>

Policy
virus Virus name Policy
x-mailer Email client Message