Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
lincolnwebber
Participant

Threat Extraction Tags all Messages as Malicious

Hi Guys,

After configuring forwarding of logs from Cloudguard SaaS to on-prem management and exporting logs from there to syslog for SIEM correlation, the customer complains that all emails with attachments trigger threat extraction events and are seen as malicious. Can someone explain whether the solution is working as intended and if so, how should this be integrated with a SIEM to provide useful security events for email attachments?

0 Kudos
1 Reply
PhoneBoy
Admin
Admin

Actual screenshots of what is reported in the SIEM versus what is reported in the Infinity Portal would be helpful.

0 Kudos