ScanLogic group event classes
In the body of CEF messages for classes of ScanLogic group events, you can use keys in accordance with their semantics (see the table below).
Permissible values of the fields for classes of ScanLogic group events
Event class |
Key |
Value |
---|---|---|
All ScanLogic group classes |
cs1 |
Message ID. |
cs1Label |
Its value is always |
|
src |
IP address of the server from which the message was received, in IPv4 format. |
|
c6a2 |
IP address of the server from which the message was received, in IPv6 format. |
|
act |
Final action that was performed on the message. |
|
suser |
Mail sender. The address is taken from the SMTP session. |
|
duser |
List of message recipients. The addresses are taken from the SMTP session. |
|
cs2 |
List of rules. |
|
cs2Label |
Its value is always |
|
outcome |
Scan status. |
|
KSMGMessageSubject |
Message subject. |
|
KSMGRuleNames |
Rule names. |
|
KSMGAvDetectionMethods |
Detection method. |
|
fileHash |
Hash of the MIME part of the message. |
|
KSMGMessageHashType |
Hash algorithm. |
|
KSMGBackupResult |
Indicates whether the message was sent to Backup. |
|
KSMGApStatus |
Result of scan by the Anti-Phishing module. |
|
KSMGMlfStatus |
Result of link scan. |
|
KSMGAvStatus |
Result of scan by the Anti-Virus module. |
|
KSMGAsStatus |
Result of scan by the Anti-Spam module. |
|
KSMGCfStatus |
Result of scan by the Content Filtering module. |
|
KSMGMaStatus |
Result of Mail Sender Authentication. |
|
KSMGKtStatus |
Result of scan by the KATA Protection module. |
|
LMS_EV_SCAN_LOGIC_ALL_NOT_PROCESSED |
reason |
Reason for the event. Possible values:
|
LMS_EV_SCAN_LOGIC_AV_STATUS |
act |
Final action that was performed on the message. Possible values:
|
cs4 |
Detection method. Possible values:
|
|
fsize |
Message size. |
|
reason |
Reason for the event. Possible values:
|
|
outcome |
Scan status. Possible values:
|
|
LMS_EV_SCAN_LOGIC_AS_STATUS |
act |
Final action that was performed on the message. Possible values:
|
cs3 |
List of recipients of notifications about triggered rules for which a notification is configured with the original message in an attachment. The addresses are taken from the SMTP session. |
|
cs3Label |
Its value is always |
|
cs4 |
Detection method. Possible values are subject to change and do not depend on the product version. |
|
cs4Label |
Its value is always |
|
fsize |
Message size. |
|
outcome |
Scan status. Possible values:
|
|
reason |
Reason for the event. Possible values:
|
|
LMS_EV_SCAN_LOGIC_AP_STATUS |
act |
Final action that was performed on the message. Possible values:
|
cs3 |
List of recipients of notifications about triggered rules for which a notification is configured with the original message in an attachment. The addresses are taken from the SMTP session. |
|
cs3Label |
Its value is always |
|
cs4 |
Detection method. Possible values:
|
|
cs4Label |
Its value is always |
|
fsize |
Message size. |
|
outcome |
Scan status. Possible values:
|
|
reason |
Reason for the event. Possible values:
|
|
LMS_EV_SCAN_LOGIC_MLF_STATUS |
act |
Final action that was performed on the message. Possible values:
|
cs3 |
List of recipients of notifications about triggered rules for which a notification is configured with the original message in an attachment. The addresses are taken from the SMTP session. |
|
cs3Label |
Its value is always |
|
cs4 |
Detection method. Possible values:
|
|
cs4Label |
Its value is always |
|
fsize |
Message size. |
|
outcome |
Scan status. Possible values:
|
|
reason |
Reason for the event. Possible values:
|
|
LMS_EV_SCAN_LOGIC_MA_STATUS |
act |
Final action that was performed on the message. Possible values:
|
cs3 |
List of recipients of notifications about triggered rules for which a notification is configured with the original message in an attachment. The addresses are taken from the SMTP session. |
|
cs3Label |
Its value is always |
|
cs4 |
SPF status. Possible values:
|
|
cs4Label |
Its value is always |
|
cs5 |
DKIM status. |
|
cs5Label |
Its value is always |
|
cs6 |
DMARC status. |
|
cs6Label |
Its value is always |
|
fsize |
Message size. |
|
outcome |
Scan status. Possible values:
|
|
reason |
Reason for the event. Possible values:
|
|
LMS_EV_SCAN_LOGIC_KT_STATUS |
act |
Final action that was performed on the message. Possible values:
|
cs3 |
List of recipients of notifications about triggered rules for which a notification is configured with the original message in an attachment. The addresses are taken from the SMTP session. |
|
cs3Label |
Its value is always |
|
cs4 |
Reason for skipping the scan. Possible values:
|
|
cs4Label |
Its value is always |
|
cs5 |
Name of the user account that extracted the message from KATA Quarantine. |
|
cs5Label |
Its value is always |
|
fsize |
Message size. |
|
outcome |
Scan status. Possible values:
|
|
reason |
Reason for the event. Possible values:
|
|
LMS_EV_SCAN_LOGIC_CF_STATUS |
act |
Final action that was performed on the message. Possible values:
|
cs3 |
List of recipients of notifications about triggered rules for which a notification is configured with the original message in an attachment. The addresses are taken from the SMTP session. |
|
cs3Label |
Its value is always |
|
cs4 |
List of applied expression names. |
|
cs4Label |
The value is always |
|
fsize |
Message size. |
|
outcome |
Scan status. Possible values:
|
|
reason |
Reason for the event. Possible values:
|
|
LMS_EV_SCAN_LOGIC_PART_RESULT |
cn1 |
Number of objects disinfected or deleted based on Anti-Virus scan results. For archives only. |
cn1Label |
Its value is always |
|
cs3 |
Unscanned files. |
|
cs3Label |
Its value is always |
|
cs4 |
List of names of detected threats. |
|
cs4Label |
Its value is always |
|
cs5 |
List of triggered Content Filtering expressions. |
|
cs5Label |
The value is always |
|
fname |
File name. |
|
fsize |
Size of the MIME part of the message. |
|
outcome |
Scan status. Possible values:
|
|
reason |
Reason why a scan by the Anti-Virus module was not performed. Possible values:
|
|
LMS_EV_SCAN_LOGIC_URL |
cs3 |
URL. |
cs3Label |
The value is always |
|
LMS_EV_SCAN_LOGIC_MESSAGE_BACKUP |
act |
Final action that was performed on the message. Possible values:
|
fsize |
Message size. |
|
reason |
Reason for the event. Possible values:
|
|
LMS_EV_SCAN_LOGIC_MESSAGE_RESULT |
fsize |
Message size. |
Each class of ScanLogic group events can contain only keys that are relevant to it (see the table below).
Relevant keys for classes of ScanLogic group events
Event class |
Relevant keys |
---|---|
LMS_EV_SCAN_LOGIC_ALL_NOT_PROCESSED |
cs1, cs1Label, src, c6a2, act, fsize, suser, duser, KSMGMessageSubject, reason |
LMS_EV_SCAN_LOGIC_AS_STATUS |
cs1, cs1Label, src, c6a2, act, fsize, suser, duser, KSMGMessageSubject, cs2, cs2Label, cs4, cs4Label, reason, outcome, KSMGRuleNames |
LMS_EV_SCAN_LOGIC_AV_STATUS |
cs1, cs1Label, src, c6a2, act, fsize, suser, duser, KSMGMessageSubject, cs2, cs2Label, cs3, cs3Label, cs4, reason, outcome, KSMGRuleNames |
LMS_EV_SCAN_LOGIC_MLF_STATUS |
cs1, cs1Label, src, act, fsize, suser, duser, cs2, cs2Label, cs3, cs3Label, reason, cs4, cs4Label, outcome, KSMGRuleNames |
LMS_EV_SCAN_LOGIC_AP_STATUS |
cs1, cs1Label, src, c6a2, act, fsize, suser, duser, cs2, cs2Label, cs3, cs3Label, reason, cs4, cs4Label, outcome, KSMGRuleNames, KSMGMessageSubject |
LMS_EV_SCAN_LOGIC_KT_STATUS |
cs1, cs1Label, src, c6a2, act, fsize, suser, duser, cs2, cs2Label, cs3, cs3Label, cs4, cs4Label, cs5, cs5Label, reason, suser, outcome, KSMGMessageSubject, KSMGRuleNames |
LMS_EV_SCAN_LOGIC_MA_STATUS |
cs1, cs1Label, src, c6a2, act, fsize, suser, duser, cs2, cs2Label, cs3, cs3Label, reason, cs4, cs4Label, cs5, cs5Label, cs6, cs6Label, outcome, KSMGMessageSubject, KSMGRuleNames |
LMS_EV_SCAN_LOGIC_CF_STATUS |
cs1, cs1Label, src, c6a2, act, fsize, suser, duser, cs2, cs2Label, cs3, cs3Label, reason, cs4, cs4Label, outcome, KSMGMessageSubject, KSMGRuleNames |
LMS_EV_SCAN_LOGIC_PART_RESULT |
cs1, cs1Label, src, c6a2, act, suser, duser, reason, outcome, KSMGMessageSubject, KSMGRuleNames, cn1, cn1Label, cs2, cs2Label, cs3, cs3Label, cs4, cs4Label, cs5, cs5Label, fname, fileHash, KSMGMessageHashType, fsize, KSMGAvDetectionMethods |
LMS_EV_SCAN_LOGIC_URL |
cs1, cs1Label, src, c6a2, suser, duser, KSMGMessageSubject, KSMGRuleNames, cs2, cs2Label, cs3, cs3Label, KSMGApStatus, KSMGMlfStatus |
LMS_EV_SCAN_LOGIC_MESSAGE_BACKUP |
cs1, cs1Label, src, c6a2, act, fsize, suser, duser, reason, cs2, cs2Label, KSMGMessageSubject, KSMGRuleNames |
LMS_EV_SCAN_LOGIC_MESSAGE_RESULT |
cs1, cs1Label, src, c6a2, act, suser, duser, KSMGMessageSubject, KSMGRuleNames, KSMGBackupResult, fsize, cs2, cs2Label, KSMGAvStatus, KSMGAsStatus, KSMGApStatus, KSMGMlfStatus, KSMGCfStatus, KSMGMaStatus, KSMGKtStatus |