you probably need to set extended-utm-log.
I always set the UTM profiles for customer at the beginning to see what is working and what not.
For example for Email filter:
# config spamfilter profile
# edit EF1_proxy
# set extended-utm-log enable
# config smtp
# set log enable
-- the same for pop3, imap etc.
If you do not have SSL inspection, the encrypted email communication will not be logged.
I also set a webfilter profile for monitoring in the GUI and enable extended-utm-log in CLI. Also enable log-all-urls under the profile.
NSE 8, CCNP R+S