Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
imamuzic
Collaborator
Jump to solution

Threat Emulation policy action "Send"

Hi guys,

 

What policy action of type "Send" means in context of Threat Emulation with ICAP? I have a TP gateway (ICAP server) with remote emulation to local TE appliance. 

Please see the screenshot attached. 

 

Best Regards,

Igor

 

 

 

2 Solutions

Accepted Solutions
PhoneBoy
Admin
Admin

It would seem to indicate this file was sent for emulation.

View solution in original post

Ronit_Segal
Employee
Employee

As per RnD:

The logs look like a bug, since “Send” is a feature reserved for DLP.

 ICAP sends 'monitor', 'allow', 'prevent' logs.

Therefore, in this case. it is better to open a support ticket.

View solution in original post

0 Kudos
6 Replies
PhoneBoy
Admin
Admin

It would seem to indicate this file was sent for emulation.

imamuzic
Collaborator

Great, thanks. That makes sense. I think that "Lggging and Monitoring Admin Guide" under "Using the Action Filter" should be updated to reflect what you wrote above as its current version is a bit misleading about "Send" action:

"User decided to continue transmission after DLP capture. An administrator with full permissions or with the View/Release/Discard DLP messages permission can also decide to continue transmission. Email notification is sent to the user."

0 Kudos
PhoneBoy
Admin
Admin

Possible this is used in both situations.
In any case, tagging @Sergei_Shir 

0 Kudos
Ronit_Segal
Employee
Employee

As per RnD:

The logs look like a bug, since “Send” is a feature reserved for DLP.

 ICAP sends 'monitor', 'allow', 'prevent' logs.

Therefore, in this case. it is better to open a support ticket.

0 Kudos
the_rock
MVP Diamond
MVP Diamond

Exactly means what Phoneboy said.

Best,
Andy
"Have a great day and if its not, change it"
0 Kudos
Ronit_Segal
Employee
Employee

According to @Ran :

Not sure why but I think ICAP generate this weird log. TE does generate these kind of logs.

 

This looks like a bug, not sure why this log is created like this.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events