Store Transaction Log Format

Message store XML transaction logging is enabled by setting the  option to. Both the MTA and store have legacy transaction log formats that are deprecated in favor of the XML format. For a discussion of the MTA XML logging format, see the log_format MTA option.

Each log entry is a self-closing XML entity with a two-letter entity name that contains attributes (also with two-letter names). New attributes may be added and the attributes may be re-ordered in any patch release, so use of an XML-aware parser is recommended. The content of the log is intended to be extended in a backwards-compatible format (with possible exceptions for a major release), unlike the legacy store messagetrace and server log formats which are unstable. Due to the size of transaction log files on busy systems, use of a SAX-style parser is recommended.

To control what actions are logged, use the actions option (unified configuration only). To control what attributes are logged, use the actionattributes option. Note that the MTA uses a different mechanism to control what is logged; see the Transaction logging MTA options section.

XML Log Attributes Always Present in Store Transaction log
The following attributes appear on all Store Transaction Log entries and are thus not mentioned in the event-specific descriptions below:



 - Process id (integer). Note that the MTA uses a different format for this attribute documented in the log_process option. 

 - service name (e.g., imap, pop, imquotacheck) 

 - time stamp. Both MTA & store use ISO 8601 format as of 8.0.2; but in 8.0 the store used a legacy timestamp format. 



XML Log Common Attributes
The following attributes may appear on several XML log entry event types with largely consistent meaning. When these are mentioned in the &#x27;Common&#x27; attribute list for an event type, they will be included unless disabled by the actionattributes option.



 - IMAP Mailbox name (internal form) 

 - Message id 

 - Source mailbox for copy/rename (   is destination mailbox) 

 - session id (IMAP & POP): a unique integer identifier for a client session/connection. </li>

 - transport information (MTA & store). Prior to 8.0.2, the store only included the client&#x27;s address and port in this field. </li>

 - User name: the canonial authorization user identity (the permanent identity of the primary mail account being accessed). For more information on user identifiers see User Identifiers. Can also be &#x5b;unauthenticated&#x5d; when appropriate. For the  action, the string "Admin" is used when this can&#x27;t be determined (typically for mboxutil). </li>

</ul>

XML Log Entity Names and Specific Attributes:
- Access Control Change (IMAP only). Attributes include:



 Common:,  , </li>

 - Old ACL using permanent user identifiers. New in 8.0.2. </li>

 - New ACL using permanent user identifiers. New in 8.0.2. </li>

 - Old and new ACL with &#x27;:&#x27; delimiter (Messaging Server prior to 8.0.2 only). </li>

</ul>

- Big Memory Allocation Event (new in MS 8.0.2.2). Attributes include:



 - Big memory function (malloc, calloc, realloc) </li>

 - Bytes allocated </li>

 - Source filename of allocation </li>

 - Source line number of allocation </li>

</ul>

- Copy Message Event (new in MS  8.0.2.2). Attributes include:



 Common:,  , </li>

 - number of copied messages </li>

 - total size of copied messages </li>

<li> - source IMAP UID set for copy operation </li>

<li> - destination IMAP UID set for copy operation </li>

<li> - IMAP UIDVALIDITY for destination </li>

</ul>

- Socket Connection (open/close). Attributes include:

<ul>

<li> Common: , </li>

<li> - Action code. First letter is &#x27;O&#x27; for connection open and &#x27;C&#x27; for connection close. Subsequent letters are extensible flags. See MTA transaction log entry format for the meaning of the subsequent flags for the MTA. Subcodes that can be used by the MMP and store include: <ul>

<li> - Closed due to DNS RBL </li>

<li> - Closed due to internal/config error </li>

<li> - Closed due to connection limit </li>

<li> - Closed due to broken pipe </li>

<li> - Closed due to connection reset </li>

<li> - Closed due to socket error </li>

<li> - Closed due to timeout </li>

<li> - Closed due to TCP Access wrap filter </li>

<li> - Closed due to force kill, imsconnutil -k </li>

</ul>

</li>

<li> - Store only: will be &#x27;ssl&#x27; if SSL was used at connection open time or empty string if SSL was not used. </li>

<li> - bytes received during connection (new in MS 8.0.2). </li>

<li> - bytes sent during connection (new in MS 8.0.2). </li>

<li> - flag update page scan count (new in MS 8.0.2.2). A large number indicates potentially significant server CPU consumed by this user&#x27;s client. </li>

<li> - number of mailboxes selected during session (new in MS 8.0.2, imap/pop only). </li>

<li> - In 8.0, contains unstructured information about the connection at connection close. Removed in MS 8.0.2 in favor of separate attributes. </li>

<li> - Reason connection was rejected (new in 8.0.2.1,  MMP only) </li>

<li> - Search body count (new in MS 8.0.2.2). This counts the number of messages mapped for searching purposes by this user. This does not count searches performed by ISS, DSE or elastic search. </li>

<li> - Session duration with HHH:MM:SS format (new in MS 8.0.2). </li>

<li> - Time spent on DNS RBL lookups in milliseconds (new  in MS 8.0.2.1, MMP only). </li>

</ul>

- Expunge Action (store IMAP expunge/expire). Attributes include:

<ul>

<li> Common:,  , </li>

<li> - Messages in mailbox (post-expunge). Prior to MS 8.0.2 this attribute combined  with the pre-expunge message count using a &#x27;/&#x27; delimiter. </li>

<li> - Messages changed (for  action, messages expunged). New in MS 8.0.2. </li>

<li> - Message Id. Note that when this attribute is enabled, a separate expunge log entry is created for each message. If this attribute is not enabled, then only one expunge entry is created for each expunge operation. </li>

<li> - Node name (local host name or remote client IP & port). </li>

</ul>

- Flag Change Action (store +/-flags). New in MS 8.0.2.2.

<ul>

<li> Common: , </li>

<li> - Action code; one of "S" for set, "C" for clear  or "R" for replace. </li>

<li> - Flag list (space delimited) </li>

<li> - Number of messages changed </li>

<li> - IMAP modification sequence for this change </li>

<li> - UIDs changed in IMAP uid set format </li>

<li> - IMAP UIDVALIDITY for mailbox </li>

</ul>

- Fetch Message Action (POP & IMAP only). Attributes include:

<ul>

<li> Common:,  ,  , </li>

<li> - Fetch decoding (b64, qp or omitted) (8.0.2 IMAP only) </li>

<li> - Offset to message part in stored message (8.0.2 IMAP only) </li>

<li> - Fetch offset into message part (8.0.2 IMAP only) </li>

<li> - Alternate for  code (8.0.1 POP only) </li>

<li> - Actual bytes fetched. For 8.0.2 this is a number. For earlier 8.0 versions, this instead contains a string combining: fetch start offset ":" fetch data size or "Binary:" followed by the offset into the message, the offset into the decoded data and the fetch data size (IMAP only). </li>

<li> - IMAP UID for message (8.0.2 IMAP only) </li>

</ul>

- Login/Authenticate Action (store/MMP). Attributes  include:

<ul>

<li> Common:,  , </li>

<li> - Integer authentication error code;  see   for description. Omitted if not known (MMP  only, new in MS 8.0.2.1) </li>

<li> - Authentication Type (SASL mechanism name, ssl-port-cert, anonymous or plaintext) </li>

<li> - badness delay (seconds) before next  authentication attempt (MMP only, new in MS 8.0.2.1) </li>

<li> - Ciphersuite used followed by TLS version. If SSL/TLS is not used, this will be &#x27;noSSL&#x27;. </li>

<li> - Authentication Error or Reply </li>

<li> - Proxy host name from mailHost or affinity config  (MMP only, new in MS 8.0.2.1). </li>

<li> - Proxy transport information (MMP only, new in MS  8.0.2.1) </li>

<li> - User authentication identity. This is the user whose password is used to authenticate; which differs from  when administrative proxy authentication is used (new in MS 8.0.2). </li>

<li> - Original user identity. This is the identity  originally specified by the client prior to canonicalization (MMP   only, new in MS 8.0.2.1) </li>

</ul>

- Logout action;  (POP-only, only if poplogmboxstat is set). Attributes include:

<ul>

<li> Common:,  , </li>

<li> - Unix timestamp of POP login. </li>

<li> - Number of messages not marked for deletion. </li>

<li> - Total bytes in messages not marked for deletion. </li>

</ul>

- Message Append Action. Attributes include:

<ul>

<li> Common:,  ,  , </li>

<li> - alternate name for session identifier (MS 8.0.1 only). </li>

<li> - Total bytes in the appended message. </li>

<li> - IMAP UID for message </li>

<li> - IMAP UIDVALIDITY for message </li>

</ul>

,,   - Mailbox Create,   Delete, Rename Actions (IMAP only). Attributes include:

<ul>

<li> Common:,  ,  , </li>

<li> - partition name (classic store only) </li>

<li> - Mailbox Rename duration (introduced in 8.1.0.1) </li>

</ul>

,  - Mailbox Subscribe,   Unsubscribe Actions (IMAP only). Attributes include:

<ul>

<li> Common:,  , </li>

<li> - namespace (IMAP2bis only) </li>

</ul>

- Quota Change (IMAP only). Attributes include:

<ul>

<li> Common: , </li>

<li> - Quota Root </li>

<li> - Disk storage quota (number in KB) </li>

</ul>

- Quota Exceeded Action (quotacheck tool only). Attributes include:

<ul>

<li> Common: </li>

<li> - Disk storage quota (number in KB) </li>

<li> - Disk storage usage (number in KB) </li>

<li> - Message count quota (number) </li>

<li> - Message count used (number) </li>

<li> - Overquota Trigger (numeric percentage) </li>

<li> - Quota Rule Name (&#x27;General&#x27; if not using a rule file) </li>

</ul>

- Search, Sort or Thread Mailbox (IMAP only). Attributes include: (new in 8.0.2.2)

<ul>

<li> Common: , </li>

<li> - Number of matching messages </li>

<li> - Number of mailboxes searched (only counts local  mailboxes when remote shared folders are present). </li>

<li> - Error message on search failure (omitted on success) </li>

<li> - Search body count. This counts the number of  messages mapped for searching purposes for this search. This does not  count searches performed by ISS, DSE or Elasticsearch. </li>

<li> - Search flags (Q=Message sequence search, U=Uid search, I=iss, D=dse, E=elastic, C=classic, T=Thread, X=Context,  S=Sort, M=multi-mailbox search) </li>

<li> - Time passed during search in milliseconds (omitted if 0) </li>

</ul>

- Select Mailbox (IMAP only). Attributes include:

<ul>

<li> Common:,  ,  , </li>

</ul>

See also:
 * User identifiers
 * allocsize Option
 * activate Option