Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Evren_Buyer
Contributor

How to get e-mail forensic data using the query syntax?

Hi Everyone !

I'm new to Threat Emulation (TE) and just located my GW as next hop MTA and started to use TE in the middle of my mail system as best practices overview.

Internet-->SMTP Security GW ---> CP MTA (Threat Emulation,Threat Extracion, Anti-Spam, E-Mail Security BLADES ON)---> Exchange Server ---> E-Mail Client

My question is to get forensic data those mails pass through the CP Threat Prevention system.

When I made a query in the log according to the sender address like below is available to be filtered, but when I try to make a query according to receipent I'm getting thousands of internal user data, cause my AD name the as my e-mail address...

I researched the query methods and in the query pane "other filelds" I found out "email_address:" and tried to make a query with that but no success !!! Nothing came out....

For e-mail forensic like blocked and extracted e-mails I need to make queries according to e-mail receipent, e-mail sender, e-mail subject, all of them etc... Does anyone know how to do that? I also have Smart Event license and server...

6 Replies
This widget could not be displayed.

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Wed 01 May 2024 @ 02:00 PM (EDT)

    South US: HTTPS Inspection Best Practices

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Wed 01 May 2024 @ 02:00 PM (EDT)

    South US: HTTPS Inspection Best Practices

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82
    CheckMates Events