What exactly do you mean by 'log'?
Are you referring to an ATD sandboxing report? Which files and format are included?
a log indicating, for example, a successful login/logout or one like this https://community.emc.com/ideas/4362
I'm working with IBM QRadar SIEM and I have to create a parser for this type of log source.
I hope I have been clearer.
You can find the syslog format for analysis results and also audit logs on the ATD Product Guide:
Page 116 of the PDF - Configure the Syslog settings