Document toolboxDocument toolbox

Email

This group includes tags that start with the level mail. These tags identify data generated by email servers.

Company Product / service Valid tags

Agari Phishing Defense

  • mail.agari.phishing_defense.policy_events
  • mail.agari.phishing_defense.messages

Check more info about these parsers

Cisco Email Security Appliance

  • mail.cisco.esa.stdout

Dovecot email server

  • mail.dovecot.audit

Microsoft Exchange Server


  • mail.exchange.messagetracking
  • mail.exchange.ncsa
  • mail.exchange.w3c

FortiMail: Secure Email Gateway

  • mail.fortinet.event.admin
  • mail.fortinet.event.config
  • mail.fortinet.event.ha
  • mail.fortinet.event.smtp
  • mail.fortinet.event.update
  • mail.fortinet.spam
  • mail.fortinet.statistics
  • mail.fortinet.virus.infected

KnowBe4

  • mail.knowbe4.phisher.webhooks

Check more info about these parsers

Mimecast Secure Email Gateway
Mimecast Targeted Threat Protection

  • mail.mimecast.archive
  • mail.mimecast.archive.messageview
  • mail.mimecast.archive.search
  • mail.mimecast.audit.events
  • mail.mimecast.siem
  • mail.mimecast.siem.delivery
  • mail.mimecast.siem.jrnl
  • mail.mimecast.siem.process
  • mail.mimecast.siem.receipt
  • mail.mimecast.ttp
  • mail.mimecast.ttp.attachment
  • mail.mimecast.ttp.impersonation
  • mail.mimecast.ttp.url
  • mail.mimecast.message.list
  • mail.mimecast.message.summary
  • mail.mimecast.threat.feed
  • mail.mimecast.account.dashboard

Check more info about these parsers

Postfix mail server


  • mail.postfix.error
  • mail.postfix.info

Proofpoint Email Protection

  • mail.proofpoint.tapsiem_v2
  • mail.proofpoint.sendmail
  • mail.proofpoint.stdout
  • mail.proofpoint.trap
  • mail.proofpoint.tapsiem_v2.clicksblocked
  • mail.proofpoint.tapsiem_v2.clickspermitted
  • mail.proofpoint.tapsiem_v2.messagesblocked
  • mail.proofpoint.tapsiem_v2.messagesdelivered

Check more info about these parsers

Trend Micro InterScan Messaging Security Suite (IMSS)

  • mail.smtp.as400alerts
  • mail.smtp.dlp
  • mail.smtp.general
  • mail.smtp.imss-polevt
  • mail.smtp.spam-eti
  • mail.smtp.spam-spain
  • mail.smtp.spam-tis
  • mail.smtp.spam-trap