Views:
Field Name
Type
General Field
Description
Example
Products
actResult
  • string[]
-
The action result
  • Success
  • Collaboration Sensor
actionName
  • string
-
The user or service action
  • UserLoggedIn
  • Collaboration Sensor
applicationId
  • string
-
The application ID
  • 11111111-1111-1111-1111-111111111111
  • Collaboration Sensor
attachmentFileHashSha256s
  • string[]
  • FileSHA2
The SHA-256 hash of the email attachment
  • 0570dfd156ee00cb7bc2a94998157cb3a29292b9e9feed82d4b6c7d2c6bdd9d4
  • 2d96ebbbc5a5687b0f18fd5620e4e5489d49a877430146bbca447fabe9c47a6e
  • 20d27422610967122439735cbcb48e4382a16e94a8b29c068e6b7d0e40466427
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
attachmentFileHashes
  • string[]
  • FileSHA1
The SHA-1 hash of the email attachment
  • acedb7898338a46f38d148d1d0456e644576d41b
  • ea6fcc4c0c1f10d71742b29e98a977d995473dd1
  • 03d8fb85556edf397d8afcafc0b13f11ecbde50c
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
attachmentFileName
  • string[]
  • FileName
The file name of the email attachment
  • image001.png
  • image002.png
  • image003.png
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
attachmentFileTlshes
  • string[]
-
The TLSH hash detected by Trend Micro Anti-Spam Engine
-
  • Trend Micro Email Security
  • Trend Micro Cloud App Security
  • Email Sensor
attachmentMd5
  • string[]
  • FileMD5
The MD5 hash of the email attachment
  • 003fa299ab119219596f952c68029810
  • 03aeabf6a745cb627ee29c05a22e58cb
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
attachmentSha1
  • string[]
  • FileSHA1
The SHA-1 hash of the email attachment
  • 03d8fb85556edf397d8afcafc0b13f11ecbde50c
  • 056a2975edffe7188c03c324ae4335f9380b57e3
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
attachmentSha256
  • string[]
  • FileSHA2
The SHA-256 hash of the email attachment
  • 29d72af5608ee5eade7c4346d3c32dfcc6b54f8fb43d977ff0306ad68b255a01
  • cb0628092ddea96bb040221b5c793dbbb792a67d0621bdfba170c07374d85801
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
attachmentSize
  • int64[]
-
The attachment file size
-
  • Trend Micro Email Security
  • Trend Micro Cloud App Security
  • Email Sensor
attachmentSource
  • string[]
-
The attachment source
  • TMASE
  • PRODUCT
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
attachmentTlsh
  • string[]
-
The TLSH hash detected by Trend Micro Anti-Spam Engine
  • 0FE18E0807B75799EF3ADD7A98D62411FEB31DAB419C913C058068A3A6B33BD114EA39
  • 7C31C9827A71A905CC6B0A73B10FE80C06F01E814AA396347F8B6F979690E9C3D75147
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
attachmentUrls
  • object_AttachmentUrl[]
-
The URLs and URL sources extracted from the email attachment
-
  • Trend Micro Email Security
  • Email Sensor
clientIp
  • string
  • IPv4
  • IPv6
The client IP
  • 10.10.10.10
  • Collaboration Sensor
cloudStorageId
  • string
-
The file or folder location ID
  • 11111111-1111-1111-1111-111111111111
  • Collaboration Sensor
cloudStorageName
  • string
-
The file or folder URL
  • https://test.trendmicro.com/sites/123
  • Collaboration Sensor
correlationId
  • string
-
The correlation ID
  • 11111111-1111-1111-1111-111111111111
  • Collaboration Sensor
eventId
  • enum_MESSAGING_EVENT_ID
-
The event ID
  • 1 - MESSAGING_EMAIL_META
  • 2 - MESSAGING_COLLABORATION_ACTIVITY
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
  • Collaboration Sensor
eventName
  • string
-
The event type
  • COLLABORATION_ACTIVITY
  • Collaboration Sensor
eventSubName
  • string
-
The event type sub-name
  • Audit.Exchange
  • Audit.Sharepoint
  • Audit.General
  • Collaboration Sensor
eventTime
  • int64
-
The time the agent detected the event
  • 1657135700000
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
extraInfo
  • string[]
-
The additional information about the sharing action
  • <ClientType>SPHomePagesWeb</ClientType>
  • Collaboration Sensor
fileExt
  • string
-
The file extension (If the object is a folder, there is no value for this field.)
  • jpg
  • Collaboration Sensor
fileName
  • string
  • FileName
The file or folder name
  • test.pdf
  • Collaboration Sensor
filterRiskLevel
  • string
-
The top-level risk level of the event
  • info
  • low
  • medium
  • Security Analytics Engine
groupId
  • string
-
The group ID for the management scope filter
  • 11111111-1111-1111-1111-111111111111
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
isExternalAccess
  • bool
-
Whether the cmdlet was run by an external user (true=external user, false=internal user in your organization)
  • true
  • Collaboration Sensor
isSensitiveInfo
  • bool
-
Whether the event contains sensitive information
  • true
  • Collaboration Sensor
logReceivedTime
  • int64
-
The time when the XDR log was received
  • 1656324260000
  • Security Analytics Engine
mExternalUid
  • string
-
The unique ID of the email
  • 11111111-1111-1111-1111-111111111111
  • Trend Micro Cloud App Security
  • Email Sensor
mailAttachmentHash
  • string
  • FileMD5
The hash value of the email attachment
  • 02ab50ee0bccadb43d6cc504928f2ff2
  • 0a0f335fb04f1acebb7500d5358321c0
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
mailBccAddresses
  • string[]
  • EmailRecipient
The BCC address in the email header
  • sample_email@trendmicro.com
  • Trend Micro Email Security
  • Trend Micro Cloud App Security
  • Email Sensor
mailCacheId
  • string
-
The internal email cache ID to identify emails in the same group mails
  • <sample_email@trendmicro.com>
  • Trend Micro Cloud App Security
  • Email Sensor
mailCcAddresses
  • string[]
  • EmailRecipient
The CC address in the email header
  • <sample_email@trendmicro.com>
  • sample_email@trendmicro.com
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
mailDirection
  • int32
-
The email traffic direction
  • 1
  • 3
  • 25
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
mailEurekaRuleIds
  • string[]
-
The list of rule IDs scanned by Eureka and detected by Trend Micro Anti-Spam Engine
  • 661030
  • 661230
  • 661267
  • Trend Micro Email Security
  • Trend Micro Cloud App Security
  • Email Sensor
mailFeatureId
  • int64[]
-
The email protocol detected by Trend Micro Anti-Spam Engine
-
  • Trend Micro Email Security
  • Trend Micro Cloud App Security
  • Email Sensor
mailFolder
  • string
-
The email folder name
  • Inbox
  • Bandeja de entrada
  • Sent Items
  • Trend Micro Cloud App Security
  • Email Sensor
mailFromAddresses
  • string[]
  • EmailSender
The From address in the email header
  • sample_email@trendmicro.com
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
mailHeaderHash
  • string
-
The email header hash detected by Trend Micro Anti-Spam Engine
  • 43f8bfc02d8f78f069c254bc17eba80b
  • aa5d16ca145f91471e482d235843aac5
  • ad8776382ea4b7cffd0961c70223162e
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
mailHelo
  • string
-
The HELO command detected by Trend Micro Anti-Spam Engine
  • HELO inpost.tmes.trendmicro.com
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
mailMetaText
  • string
-
The postman meta text detected by Trend Micro Anti-Spam Engine
  • Trend Micro Email Security
  • Email Sensor
mailMetaTraceId
  • string
-
The trace ID generated by Trend Micro Feedback Engine
  • Trend Micro Email Security
  • Email Sensor
mailMsgId
  • string
  • EmailMessageID
The email ID
  • <sample-id@trendmicro.com>
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
mailMsgSubject
  • string
  • EmailSubject
The email subject
  • Your daily briefing
  • Security alert for DeleteSecurityGroup on Account 549918006255 in Region: ap-southeast-1
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
mailReplyToAddresses
  • string[]
-
The Reply To address detected by Trend Micro Anti-Spam Engine
  • sample_email@trendmicro.com
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
mailRuleId
  • string[]
-
The rule ID of the matched rule detected by Trend Micro Anti-Spam Engine
  • 42003
  • 148036
  • 148140
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
mailScore
  • int64
-
The score assigned to the email by Trend Micro Anti-Spam Engine
-
  • Trend Micro Email Security
  • Trend Micro Cloud App Security
  • Email Sensor
mailSenderIp
  • string
-
The sender IP address
  • 10.10.10.10
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
mailSmtpFromAddresses
  • string[]
-
The sender email address
  • sample_email@trendmicro.com
  • Trend Micro Email Security
  • Email Sensor
mailSmtpOriginalRecipients
  • string[]
-
The original email recipients in the SMTP envelope
  • sample_email@trendmicro.com
  • Trend Micro Email Security
  • Email Sensor
mailSmtpRecipients
  • string[]
-
The mail recipients in the SMTP envelope after scanning
  • sample_email@trendmicro.com
  • Trend Micro Email Security
  • Email Sensor
mailSmtpTls
  • string
-
The SMTP TLS version number
  • TLS 1.2
  • TLS 1.3
  • noTLS
  • Trend Micro Email Security
  • Email Sensor
mailSourceDomain
  • string
-
The email domain of the sender
  • example.com
  • Trend Micro Cloud App Security
  • Email Sensor
mailTagHash
  • string
-
The email tag hash detected by Trend Micro Anti-Spam Engine
  • 9ce01ebc63f408264876646e20905349
  • cf679dc99042b781106cbaccd4045ed3
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
mailTagHashRawSignature
  • string
-
The raw signature hash of the email
  • PGh0bWw+PGhlYWQ+PG1ldGEgaHR0cC1lcXVpdj0gY29udGVudD0gY2hhcnNldD0gPjxtZXRhIG5hbWU9IGNvbnRlbnQ9ID48c3R5bGU+PCEtLS0tPjwvc3R5bGU+PC9oZWFkPjxib2R5IGxhbmc9IGxpbms9IHZsaW5rPSBzdHlsZT0gPjxkaXYgY2xhc3M9ID48cCBjbGFzcz0gPjxURVhUPjwvcD48L2Rpdj48L2JvZHk+PC9odG1sPg==
  • PGh0bWw+PGhlYWQ+PG1ldGEgaHR0cC1lcXVpdj0gY29udGVudD0gY2hhcnNldD0gPjwvaGVhZD48Ym9keT48VEVYVD48L2JvZHk+PC9odG1sPg==
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
mailTextHash
  • string
-
The email text hash detected by Trend Micro Anti-Spam Engine
  • 221bab3766f6d2a2c6fcc37056511d53
  • f26f3a415103ea083ac49be6bb60f337
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
mailThreatType
  • string
-
The type of email detected by Trend Micro Anti-Spam Engine
  • suspected
  • suspected,
  • suspected, phishing
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
mailToAddresses
  • string[]
  • EmailRecipient
The Mail To address in the email header
  • sample_email@trendmicro.com
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
mailUrlHash
  • string
-
The email URL hash detected by Trend Micro Anti-Spam Engine
  • ca52197d96e4a00ce19eaf34b20c8937
  • ad50776a891bead6bf222e2b7be17724
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
mailUrlsOriginalLink
  • string[]
-
The original URL extracted from the email content
  • https://aka.ms/JoinTeamsMeeting
  • http://go.microsoft.com/fwlink/p/?LinkID=12345
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
mailUrlsRealLink
  • string[]
  • URL
The URL extracted from the email content
  • https://aka.ms/JoinTeamsMeeting
  • http://go.microsoft.com/fwlink/p/?LinkID=12345
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
mailUrlsVisibleLink
  • string[]
  • URL
The URL extracted from the email content
  • Unsubscribe
  • Android
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
mailUserAgent
  • string
-
The user agent
  • Mutt/1.4.2.2i
  • Heirloom mailx 12.5 7/5/10
  • Trend Micro Email Security
  • Trend Micro Cloud App Security
  • Email Sensor
mailWantedHeaderName
  • string[]
-
The WantedHeader key name detected by Trend Micro Anti-Spam Engine
  • CC
  • X-TM-Product-Ver
  • Received
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
mailWantedHeaderValue
  • string[]
-
The WantedHeader key value detected by Trend Micro Anti-Spam Engine
  • cloud-app-security-5.0
  • BCL:0;
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
mailWholeHeader
  • string[]
-
The name and email address of the sender in the From header detected by Trend Micro Anti-Spam Engine
  • <sample_email@trendmicro.com>
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
mailXMailer
  • string
-
The X-Mailer header of the email
  • Microsoft Outlook 16.0
  • Microsoft CDO for Windows 2000
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
mailbox
  • string
-
The primary email address
  • sample_email@trendmicro.com
  • Trend Micro Cloud App Security
  • Email Sensor
msgUuid
  • string
-
The internal email UUID to identify each email message
  • 11111111-1111-1111-1111-111111111111
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
msgUuidChain
  • string
-
The internal UUID chain for each email in Trend Micro Feedback Engine
  • 11111111-1111-1111-1111-111111111111;00000000-0000-0000-0000-000000000000
  • Trend Micro Email Security
  • Email Sensor
orgId
  • string
-
The organization ID
  • 11111111-1111-1111-1111-111111111111
  • Trend Micro Cloud App Security
  • Email Sensor
orgName
  • string
-
The tenant name
  • test.trendmicro.com
  • Collaboration Sensor
originatingServer
  • string
-
The server where the operation originated
  • TY0PR03MB6449 (15.20.5746.023)
  • Collaboration Sensor
parameters
  • string
-
The names and values of all parameters used in the cmdlet identified in the Operations property
  • [{"Name": "AlwaysDeleteOutlookRulesBlob","Value": "False"},{"Name" : "Force","Value": "False"}]
  • Collaboration Sensor
pname
  • string
-
The internal product code (deprecated)
  • 733
  • 742
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
policyTreePath
  • string
-
The policy tree path (endpoint only)
  • policyname1/policyname2/policyname3
  • Security Analytics Engine
principalName
  • string
  • UserAccount
The User Principal Name
  • sample_email@trendmicro.com
  • Collaboration Sensor
productCode
  • string
-
The product code of the product that sent the log
  • sca
  • sem
  • Security Analytics Engine
recordType
  • int32
-
The operation type
  • 1
  • 2
  • Collaboration Sensor
scanTs
  • int64
-
The time the email was scanned
  • 1657135700000
  • Trend Micro Cloud App Security
  • Email Sensor
scanType
  • string
-
The manual or real-time scan type
  • realtime_mailmeta-exchange
  • realtime_mailmeta-gmail
  • gateway_mailmetadata
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
service
  • string
-
The Microsoft 365 service where the activity occurred
  • SecurityComplianceCenter
  • AzureActiveDirectory
  • SharePoint
  • Collaboration Sensor
tags
  • string[]
-
The detected technique ID based on the alert filter
  • MITREV9.T1057
  • MITREV9.T1059.003
  • XSAE.F2924
  • Security Analytics Engine
target
  • string
-
The object accessed by a user or application
  • APCPR000000.PROD.OUTLOOK.COM/Microsoft Exchange Hosted
  • Organizations/test.trendmicro.com/test\\testRule001
  • Collaboration Sensor
targetType
  • string
-
The type of object that was accessed or modified
  • File
  • Collaboration Sensor
userAgent
  • string
-
The user agent
  • Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36
  • Collaboration Sensor
userSessionId
  • string
-
The user session ID
  • 11111111-1111-1111-1111-111111111111
  • Collaboration Sensor
userType
  • string
-
The user type
  • Regular
  • Reserved
  • Admin
  • Collaboration Sensor
uuid
  • string
-
The unique key of the log entry
  • 11111111-1111-1111-1111-111111111111
  • Security Analytics Engine