<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Threat Extraction Tags all Messages as Malicious in Email and Collaboration</title>
    <link>https://community.checkpoint.com/t5/Email-and-Collaboration/Threat-Extraction-Tags-all-Messages-as-Malicious/m-p/145444#M391</link>
    <description>&lt;P&gt;Actual screenshots of what is reported in the SIEM versus what is reported in the Infinity Portal would be helpful.&lt;/P&gt;</description>
    <pubDate>Tue, 05 Apr 2022 01:01:03 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2022-04-05T01:01:03Z</dc:date>
    <item>
      <title>Threat Extraction Tags all Messages as Malicious</title>
      <link>https://community.checkpoint.com/t5/Email-and-Collaboration/Threat-Extraction-Tags-all-Messages-as-Malicious/m-p/145434#M390</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;After configuring forwarding of logs from Cloudguard SaaS to on-prem management and exporting logs from there to syslog for SIEM correlation, the customer complains that all emails with attachments trigger threat extraction events and are seen as malicious. Can someone explain whether the solution is working as intended and if so, how should this be integrated with a SIEM to provide useful security events for email attachments?&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2022 20:55:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Email-and-Collaboration/Threat-Extraction-Tags-all-Messages-as-Malicious/m-p/145434#M390</guid>
      <dc:creator>lincolnwebber</dc:creator>
      <dc:date>2022-04-04T20:55:01Z</dc:date>
    </item>
    <item>
      <title>Re: Threat Extraction Tags all Messages as Malicious</title>
      <link>https://community.checkpoint.com/t5/Email-and-Collaboration/Threat-Extraction-Tags-all-Messages-as-Malicious/m-p/145444#M391</link>
      <description>&lt;P&gt;Actual screenshots of what is reported in the SIEM versus what is reported in the Infinity Portal would be helpful.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Apr 2022 01:01:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Email-and-Collaboration/Threat-Extraction-Tags-all-Messages-as-Malicious/m-p/145444#M391</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-04-05T01:01:03Z</dc:date>
    </item>
  </channel>
</rss>

