Mail Security Log Format

Field type

Field name

Description

Example value

CEF header

CEF:Version

CEF version.

CEF:0

Device Vendor

Product vendor.

UserGate

Device Product

Product type.

NGFW

Device Version

Product version.

7

Source

Log type.

mailsecurity

Name

Source type.

log

Threat Level

Application threat level.

Available values:

  • 0: info

  • 6: warning

  • 8: error

  • 10: critical

CEF [extension]

rt

Time when the event was received (in milliseconds since January 1, 1970).

1652344423822

deviceExternalId

The unique name of the device that generated the event.

utmcore@einersonstal

act

Action taken by the device according to the configured policies.

mark

suser

The username.

user_example (Unknown, if the user is unknown)

cs1Label

Indicates the rule name.

Rule

cs1

Name for the mail security rule.

Mail security rule

src

Source IPv4 address.

194.226.127.130

spt

Source port

Values: 0-65535.

cs2Label

Indicates the source zone.

Source Zone

cs2

Source zone

Untrusted

cs3Label

Indicates the country of the traffic source.

Source Country

cs3

Traffic source country.

AE (a two-letter country code is displayed)

dst

Destination IPv4 address.

10.10.10.10

dpt

Destination port

Values: 0-65535.

cs4Label

Indicates the traffic destination zone.

Destination Zone

cs4

Traffic destination zone name.

Trusted

cs5Label

Indicates the country of the traffic destination.

Destination Country

cs5

The destination country.

AE (a two-letter country code is displayed)

app

Application layer protocol

SMTP

in

Number of transmitted inbound bytes (data transferred from the source to the destination).

10

out

Number of transmitted outbound bytes (data transferred from the destination to the source).

10

flexString1Label

Indicates the sender's address.

From

flexString1

Sender's email.

sender@example.com

cs6Label

Indicates the recipient's address.

To

cs6

Recipient's email.

receiver@example.com

cn1Label

Indicates the number of packets transmitted from the source to the destination.

Packets sent

cn1

Number of packets transmitted from the source to the destination.

3

cn2Label

Indicates the number of packets transmitted from the destination to the source.

Packets received

cn2

Number of packets transmitted from the destination to the source.

1