Field Name |
Type |
General Field |
Description |
Example |
Products |
---|---|---|---|---|---|
attachmentFileHashSha256s |
string |
|
The SHA-256 hash of the email attachment |
|
|
attachmentFileHashes |
string |
|
The SHA-1 hash of the email attachment |
|
|
attachmentFileName |
string |
|
The file name of the email attachment |
|
|
attachmentMd5 |
string |
|
The MD5 hash of the email attachment |
|
|
attachmentSha1 |
string |
|
The SHA-1 hash of the email attachment |
|
|
attachmentSha256 |
string |
|
The SHA-256 hash of the email attachment |
|
|
attachmentUrls |
AttachmentUrl[] |
- |
The URLs extracted from the email attachment |
- |
|
eventTime |
int64 |
- |
The event generation time on the agent endpoint |
|
|
filterRiskLevel |
string |
- |
The top-level risk level of the event |
|
|
mailAttachmentHash |
string |
|
The hash value of the email attachment |
|
|
mailBccAddresses |
string |
|
The BCC address in the email header |
|
|
mailCcAddresses |
string |
|
The CC address in the email header |
|
|
mailDirection |
int32 |
- |
The email traffic direction |
|
|
mailFromAddresses |
string |
|
The Mail From address in the email header |
|
|
mailMsgId |
string |
|
The email ID |
|
|
mailMsgSubject |
string |
|
The email subject |
|
|
mailSenderIp |
string |
- |
The email sender IP address |
|
|
mailSmtpOriginalRecipients |
string |
- |
The original email recipients in the SMTP envelope |
|
|
mailSmtpRecipients |
string |
- |
The mail recipients in the SMTP envelope after scanning |
|
|
mailSourceDomain |
string |
- |
The email domain of the sender |
|
|
mailToAddresses |
string |
|
The Mail To address in the email header |
|
|
mailUrlsRealLink |
string |
|
The URL extracted from the email content |
|
|
mailUrlsVisibleLink |
string |
|
The URL extracted from the email content |
|
|
mailbox |
string |
- |
The primary email address |
|
|
msgUuid |
string |
- |
The internal email UUID to identify each email message |
|
|
orgId |
string |
- |
The Cloud App Security organization ID |
|
|
pname |
string |
- |
The internal product code (deprecated) |
|
|
productCode |
string |
- |
The product code of the product that sent the log |
|
|
scanType |
string |
- |
The manual or real-time scan |
|
|
tags |
string |
- |
The detected MITRE technique ID based on the alert |
|
|
uuid |
string |
- |
The unique key of the log entry |
|
|