Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Table of Contents
maxLevel2
typeflat

Introduction

The tags beginning with mail.agari identify events generated by Fortra's Agari Phishing Defense.

Valid tags and data tables

The full tag must have 4 levels. The first two are fixed asmail.agari. The third level identifies the type of events sent, and the fourth level indicates the event subtype. 

...

Technology

...

Brand

...

Type

...

Subtype

...

mail

...

agari

...

  • policy_events

  • messages

These are the valid tags and corresponding data tables that will receive the parsers' data:

TagTags

Data tabletables

mail.agari.phishing_defense.policy_events

mail.agari.phishing_defense.policy_events

mail.agari.phishing_defense.messages

mail.agari.phishing_defense.messages

How is the data sent to Devo?

To send logs to these tables, Devo provides a collector that you can download and use to send the required events to your Devo domain. You can learn how to use it in this article on Collector for Agari Phishing Defense.

Table structure

These are the fields displayed in these tables:

Anchor
tag1
tag1
mail.agari.phishing_defense.policy_events

Field

Type

Extra fields

eventdate

timestamp

 

hostname

str

 

alert_definition_name

str

 

created_at

timestamp

 

id

int8

 

notified_original_recipients

bool

 

summary

bool

 

updated_at

timestamp

 

admin_recipients

str

 

policy_action

str

 

policy_enabled

bool

 

hostchain

str

 

tag

str

 

rawMessage

str

 

Anchor
tag2
tag2
mail.agari.phishing_defense.messages

Field

Type

Extra fields

eventdate

timestamp

 

hostname

str

 

attachment_sha256

str

 

domain_tags

str

 

has_attachment

str

 

ip

ip4

 

message_id

str

 

ptr_name

str

 

sbrs

str

 

id

str

 

policy_ids

str

 

attachment_extensions

str

 

attachment_filenames

str

 

authenticity

str

 

to_email

str

 

reply_to

str

 

timestamp_ms

timestamp

 

date

str

 

from_email

str

 

from_domain

str

 

subject

str

 

domain_reputation

str

 

message_trust_score

str

 

message_details_link

str

 

attack_types

str

 

enforcement_action

str

 

enforcement_result

str

 

hostchain

str

 

tag

str

 

rawMessage

str