Document toolboxDocument toolbox

mail.trend_micro

Introduction

The tags beginning with mail.trend_micro identify events generated by Trend Micro Email Security.

Valid tags and data tables 

The full tag must have 4 levels. The first two are fixed as mail.trend_micro. The third level identifies the type of events sent. The fourth level indicates the event subtype.

These are the valid tags and corresponding data tables that will receive the parsers' data:

Product / Service

Tags

Data tables

Product / Service

Tags

Data tables

Trend Micro Email Security

mail.trend_micro.email_security.directory_user

mail.trend_micro.email_security.directory_user

mail.trend_micro.email_security.mail_tracking

mail.trend_micro.email_security.mail_tracking

mail.trend_micro.email_security.policy_event

mail.trend_micro.email_security.policy_event

For more information, read more About Devo tags.

How is the data sent to Devo?

You can use the Trend Micro Email Security collector to send the required events to your Devo domain. Learn more about this in this article. 

Table structure

These are the fields displayed in these tables:

mail.trend_micro.email_security.directory_user

Field

Type

Extra fields

Field

Type

Extra fields

eventdate

timestamp

 

hostname

str

 

at_devo_pulling_id

str

 

at_devo_environment

str

 

email_local_part

str

 

display_name

str

 

domain

str

 

email

str

 

hostchain

str

 ✓

tag

str

 ✓

rawMessage

str

 ✓

mail.trend_micro.email_security.mail_tracking

Field

Type

Extra fields

Field

Type

Extra fields

eventdate

timestamp

 

hostname

str

 

gen_time

timestamp

 

timestamp

timestamp

 

sender

str

 

direction

str

 

message_id

str

 

subject

str

 

size

int4

 

mail_id

str

 

recipient

str

 

action

str

 

tls_info

str

 

header_from

str

 

header_to

str

 

sender_ip

str

 

delivered_to

str

 

attachments

str

 

embedded_urls

str

 

details

str

 

at_devo_pulling_id

str

 

at_devo_environment

str

 

hostchain

str

 ✓

tag

str

 ✓

rawMessage

str

 ✓

mail.trend_micro.email_security.policy_event

Field

Type

Extra fields

Field

Type

Extra fields

eventdate

timestamp

 

hostname

str

 

timestamp

timestamp

 

gen_time

timestamp

 

event_type

str

 

event_subtype

str

 

domain_name

str

 

sender

str

 

header_from

str

 

recipients

str

 

header_to

str

 

direction

str

 

message_id

str

 

subject

str

 

size

int4

 

policy_name

str

 

policy_action

str

 

details

str

 

at_devo_pulling_id

str

 

at_devo_environment

str

 

hostchain

str

 ✓

tag

str

 ✓

rawMessage

str

 ✓