Document toolboxDocument toolbox

mail.proofpoint.pod

Introduction

This union table collects information from a set of tables containing Dynamic Host Configuration Protocol (DHCP) data.

Source tables

The information displayed is extracted from the following tables:

  • mail.proofpoint.pod.events

  • mail.proofpoint.pod.isolation

  • mail.proofpoint.pod.maillog

  • mail.proofpoint.pod.message

Table structure

This is the set of columns displayed by this union table, which is the result of the collection of columns present in all source tables: 

Extra columns

Fields marked as Extra in the table below are not shown by default in data tables and need to be explicitly requested in the query. You can find them marked as Extra when you perform a query so they can be easily identified. Learn more about this in  Selecting unrevealed columns.

Field

Type

Extra fields

Field

Type

Extra fields

eventdate

timestamp

 

connection__ip

ip4

 

connection__country

str

 

connection__resolveStatus

str

 

connection__helo

str

 

connection__sid

str

 

connection__protocol

str

 

connection__host

str

 

connection__tls__inbound__cipherBits

int4

 

connection__tls__inbound__version

str

 

connection__tls__inbound__cipher

str

 

metadata__origin__data__agent

str

 

metadata__origin__data__version

str

 

metadata__origin__data__cid

str

 

ts

str

 

msgParts

str

 

filter__qid

str

 

filter__actions

str

 

filter__durationSecs

float8

 

filter__suborgs__sender

str

 

filter__suborgs__rcpts

str

 

filter__startTime

str

 

filter__isMsgReinjected

bool

 

filter__modules__pdr__v2__rscore

int4

 

filter__modules__pdr__v2__response

str

 

filter__modules__urldefense__counts__unique

int4

 

filter__modules__urldefense__counts__rewritten

int4

 

filter__modules__urldefense__counts__total

int4

 

filter__modules__urldefense__counts__noRewriteIsExcludedDomain

int4

 

filter__modules__urldefense__counts__noRewriteIsEmail

int4

 

filter__modules__urldefense__counts__noRewriteIsSchemeless

int4

 

filter__modules__urldefense__counts__noRewriteIsUnsupportedScheme

int4

 

filter__modules__urldefense__version__engine

str

 

filter__modules__spf__domain

str

 

filter__modules__spf__result

str

 

filter__modules__zerohour__score

str

 

filter__modules__spam__charsets

str

 

filter__modules__spam__langs

str

 

filter__modules__spam__version__definitions

str

 

filter__modules__spam__version__engine

str

 

filter__modules__spam__scores__engine

int4

 

filter__modules__spam__scores__classifiers__mlx

int4

 

filter__modules__spam__scores__classifiers__suspect

int4

 

filter__modules__spam__scores__classifiers__lowpriority

int4

 

filter__modules__spam__scores__classifiers__adult

int4

 

filter__modules__spam__scores__classifiers__mlxlog

int4

 

filter__modules__spam__scores__classifiers__spam

int4

 

filter__modules__spam__scores__classifiers__malware

int4

 

filter__modules__spam__scores__classifiers__impostor

int4

 

filter__modules__spam__scores__classifiers__phish

int4

 

filter__modules__spam__scores__classifiers__bulk

int4

 

filter__modules__spam__scores__classifiers__adjust

int4

 

filter__modules__spam__scores__classifiers__ndr

int4

 

filter__modules__spam__scores__overall

int4

 

filter__modules__spam__triggeredClassifier

str

 

filter__modules__spam__safeBlockedListMatches

str

 

filter__modules__regulation__rules

str

 

filter__modules__regulation__matches

str

 

filter__quarantine__folder

str

 

filter__quarantine__rule

str

 

filter__isMsgEncrypted

bool

 

filter__disposition

str

 

filter__routes

str

 

filter__routeDirection

str

 

filter__verified__rcptsHashed

str

 

filter__verified__rcpts

str

 

filter__msgSizeBytes

int8

 

filter__origGuid

str

 

pps__agent

str

 

pps__version

str

 

pps__cid

str

 

envelope__from2

str

 

envelope__rcptsHashed

str

 

envelope__fromHashed

str

 

envelope__rcpts

str

 

msg__parsedAddresses__fromHashed

str

 

msg__parsedAddresses__toHashed

str

 

msg__parsedAddresses__to

str

 

msg__parsedAddresses__from2

str

 

msg__parsedAddresses__ccHashed

str

 

msg__parsedAddresses__cc

str

 

msg__lang

str

 

msg__normalizedHeader__fromHashed

str

 

msg__normalizedHeader__reply_to

str

 

msg__normalizedHeader__message_id

str

 

msg__normalizedHeader__from2

str

 

msg__normalizedHeader__toHashed

str

 

msg__normalizedHeader__to

str

 

msg__normalizedHeader__reply_toHashed

str

 

msg__normalizedHeader__subject

str

 

msg__normalizedHeader__x_originating_ip

str

 

msg__normalizedHeader__x_mailer

str

 

msg__normalizedHeader__return_path

str

 

msg__normalizedHeader__return_pathHashed

str

 

msg__normalizedHeader__ccHashed

str

 

msg__normalizedHeader__cc

str

 

msg__sizeBytes

int8

 

msg__header__fromHashed

str

 

msg__header__reply_to

str

 

msg__header__message_id

str

 

msg__header__from2

str

 

msg__header__toHashed

str

 

msg__header__to

str

 

msg__header__reply_toHashed

str

 

msg__header__subject

str

 

msg__header__x_originating_ip

str

 

msg__header__x_mailer

str

 

msg__header__return_pathHashed

str

 

msg__header__return_path

str

 

guid

str

 

userId

str

 

userName

str

 

url

str

 

date

timestamp

 

region

str

 

zone

str

 

disposition

str

 

categories_str

str

 

data

str

 

tls__verify

str

 

tls__version

str

 

tls__cipher

str

 

id

str

 

sm__mailer

str

 

sm__stat

str

 

sm__pri

str

 

sm__to_str

str

 

sm__xdelay

str

 

sm__relay

str

 

sm__qid

str

 

sm__dsn

str

 

sm__delay

str

 

metadata__customerId

str

 

metadata__origin__schemaVersion

str

 

msgParts__sizeDecodedBytes_str

str

 

msgParts__isVirtual_str

str

 

msgParts__detectedExt_str

str

 

msgParts__labeledCharset_str

str

 

msgParts__structureId_str

str

 

msgParts__detectedSizeBytes_str

str

 

msgParts__labeledMime_str

str

 

msgParts__detectedCharset_str

str

 

msgParts__isCorrupted_str

str

 

msgParts__sha256_str

str

 

msgParts__isProtected_str

str

 

msgParts__md5_str

str

 

msgParts__urls_str

str

 

msgParts__detectedName_str

str

 

msgParts__isDeleted_str

str

 

msgParts__isTimedOut_str

str

 

msgParts__dataBase64_str

str

 

msgParts__detectedMime_str

str

 

msgParts__disposition_str

str

 

msgParts__isArchive_str

str

 

msgParts__labeledExt_str

str

 

msgParts__sandboxStatus_str

str

 

msgParts__labeledName_str

str

 

msgParts__textExtracted_str

str

 

msg__normalizedHeader__message_id_str

str

 

msg__normalizedHeader__subject_str

str

 

msg__normalizedHeader__to_str

str

 

msg__normalizedHeader__from_str

str

 

msg__parsedAddresses__fromDisplayNames_str

str

 

msg__parsedAddresses__to_str

str

 

msg__parsedAddresses__from_str

str

 

msg__header__subject_str

str

 

msg__header__message_id_str

str

 

msg__header__from_str

str

 

msg__header__to_str

str

 

msg__sizeBytes_int4

int4

 

envelope__from

str

 

envelope__rcpts_str

str

 

filter__delivered__rcpts_str

str

 

filter__suborgs__rcpts_str

str

 

filter__modules__spam__charsets_str

str

 

filter__modules__spam__langs_str

str

 

filter__actions__rule_str

str

 

filter__actions__action_str

str

 

filter__actions__module_str

str

 

filter__actions__isFinal_str

str

 

filter__verified__rcpts_str

str

 

filter__msgSizeBytes_int4

int4

 

filter__routes_str

str

 

filter__quarantine__type

str

 

filter__quarantine__module

str

 

filter__quarantine__folderId

str

 

metadata__origin__data__version_ip4

ip4

 

hostchain

str

 

tag

str

 

rawMessage

str

 

Field transformations

Even though all source tables have several features in common, they have some particularities that make it necessary to undergo a set of transformations to harmonize them for the union table. The most common transformations comprise changes in the data type or the application of rules when several columns in the source table feed a single column in the union table. You can find below the detailed list of transformations in each source table.