mail.abnormalsecurity
Introduction
The tags beginning with mail.abnormalsecurity
identify events generated by Abnormal Security.
Valid tags and data tablesÂ
The full tag must have 3 levels. The first two are fixed as mail.abnormalsecurity
. The third level identifies the type of events sent.
These are the valid tags and corresponding data tables that will receive the parsers' data:
Product / Service | Tags | Data tables |
---|---|---|
Abnormal Security |
|
|
|
|
For more information, read more About Devo tags.
Table structure
These are the fields displayed in these tables:
mail.abnormalsecurity.cases
Field | Type | Extra fields |
---|---|---|
eventdate |
| Â |
hostname |
| Â |
caseId |
| Â |
severity |
| Â |
affectedEmployee |
| Â |
firstObserved |
| Â |
threatIds |
| Â |
analysis |
| Â |
case_status |
| Â |
remediation_status |
| Â |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
mail.abnormalsecurity.threats
Field | Type | Field transformation | Source field name | Extra fields |
---|---|---|---|---|
eventdate |
| Â | Â | Â |
hostname |
| Â | Â | Â |
threatId |
| Â | Â | Â |
abxMessageId |
| Â | Â | Â |
abxPortalUrl |
| Â | Â | Â |
subject |
| Â | Â | Â |
fromName |
| Â | Â | Â |
fromAddress |
| Â | Â | Â |
toAddresses |
| Â | Â | Â |
recipientAddress |
| Â | Â | Â |
receivedTime |
| Â | Â | Â |
sentTime |
| Â | Â | Â |
internetMessageId |
| Â | Â | Â |
autoRemediated |
| Â | Â | Â |
postRemediated |
| Â | Â | Â |
attackType |
| Â | Â | Â |
attackStrategy |
| Â | Â | Â |
attachmentCount |
| Â | Â | Â |
attackedParty |
| Â | Â | Â |
returnPath |
| Â | Â | Â |
replyToEmails_str |
| join(replyToEmails, ',') | replyToEmails | Â |
ccEmails_str |
| join(ccEmails, ',') | ccEmails | Â |
senderIpAddress |
| Â | Â | Â |
impersonatedParty |
| Â | Â | Â |
attackVector |
| Â | Â | Â |
attachmentNames_str |
| join(attachmentNames, ',') | attachmentNames | Â |
urls_str |
| urls | Â | |
urlCount |
| Â | Â | Â |
summaryInsights_str |
| summaryInsights | Â | |
remediationTimestamp |
| Â | Â | Â |
isRead |
| Â | Â | Â |
remediationStatus |
| Â | Â | Â |
senderDomain |
| Â | Â | Â |
hostchain |
|  |  | ✓ |
tag |
|  |  | ✓ |
rawMessage |
|  |  | ✓ |
Â