Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
lincolnwebber
Participant

Threat Extraction Tags all Messages as Malicious

Hi Guys,

After configuring forwarding of logs from Cloudguard SaaS to on-prem management and exporting logs from there to syslog for SIEM correlation, the customer complains that all emails with attachments trigger threat extraction events and are seen as malicious. Can someone explain whether the solution is working as intended and if so, how should this be integrated with a SIEM to provide useful security events for email attachments?

0 Kudos
1 Reply
PhoneBoy
Admin
Admin

Actual screenshots of what is reported in the SIEM versus what is reported in the Infinity Portal would be helpful.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Tue 20 May 2025 @ 11:30 AM (PDT)

    Las Vegas: Check Point Hybrid Mesh

    Wed 21 May 2025 @ 11:30 AM (MST)

    Tempe, AZ: Check Point Hybrid Mesh

    Tue 03 Jun 2025 @ 06:00 PM (EDT)

    Montreal: CPX Recap

    Tue 10 Jun 2025 @ 06:00 PM (EDT)

    Quebec City: CPX Recap
    CheckMates Events