Skip to main content
Version: 5.0

E-mail

Description

The E-mail section is designed for monitoring email traffic, spam distribution, violations of corporate email usage policies, and phishing attempts.

Displayed Data

  • Number of unique delivered / quarantined / blocked messages
  • Statistics on message delivery statuses
  • Trends in message delivery statuses
  • Trends in message volume
  • Top senders / recipients by volume / number of messages
  • Event statistics with details by senders
  • Event statistics with details by recipients

List of Dashboards

  • Email: Overview
  • Email: Sender Profile
  • Email: Recipient Profile

Data Model

The section uses the following fields from data sources. Alias used: sm_cs_email_indexes.

Categorization Fields

Field NameValue
event.kindevent
event.categoryemail
event.typeallowed | denied | info
event.actionFrom the original event.

General Purpose Fields

Email Message Parameters email

Field NameValue
email.from.addressSender's email address.
email.to.addressRecipient's email address.
email.subjectMessage subject.
email.directioninbound | outbound | unknown
email.message_idEmail message identifier.

Categorizing Derived Parameter

Field NameValue
mail_actiondelivered | quarantined | rejected | unknown

Other Fields

Field NameValue
event.originalOriginal event text.

Optional Fields

Field NameValue
msg_sizeMessage size.

Reference Tables

Below is a table of reference tables used in the section.

NameFieldsDescription
sm_cs_email_group_lookupemail.address
email_group.name
Reference table for email address groups.

Example Sources