> Source: [sk170240](https://support.checkpoint.com/results/sk/sk170240)

# sk170240 - Searching / Filtering the logs Harmony Email & Office 2.0 (Previously Cloud MTA) returns no / incorrect results

| Property | Value |
|----------|-------|
| Solution ID | sk170240 |
| Date Created | 2020-11-02 |
| Last Modified | 2021-02-24 |
| Technical Level | Advanced |
| Products | Email Security |
| Versions | Cloud |

## Symptoms

- Searching / filtering the Harmony Email \& Office 2.0 (Previously Cloud MTA) logs returns no or Incorrect results.

## Cause

There are two limitations in the product that could cause incorrect / no results to be returned:  

**1. Not all fields support free text search** - If a search string is typed without specifying the field, it will be searched in the following field and will return all logs containing this string in the following fields:  

1. Email sender (envelope and EML)
2. Email recipient
3. Email subject
4. Name of one of the attachments
5. URL
6. Email ID

For other fields, log filtering can only be done by specifying a log field and the value inside the field (e.g., email_status:"Quarantined").  
**2. Search field names different than the displayed field names**   
- the field names you can filter by are different than the ones presented in the logs view.  
Some examples:  

|-----------------|---------------|------------------------------|
| Displayed Field | Search Field  | Example                      |
| Email Sender    | from          | from:user@domain.com         |
| Email Recipient | to            | to:user@domain.com           |
| Subject         | email_subject | email_subject:"some subject" |

<br />

<br />

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
