So, how am I supposed to read such obfuscated mail alerts?
HeaderDateHour: 9Sep2020 7:23:49; ContentVersion: 5; hll_key: 8473581293994328681; Uuid: {0x5f5858d5,0x0,0x98c0a8c0,0x2288}; SequenceNum: 3; Action: redirect; Origin: FW-EXT; IfDir: <; InterfaceName: eth1.352; Alert: mail; OriginSicName: CN=FW-EXT,O=CPSMS..kg4oq9; duration: 0:00:00; last_hit_time: 9Sep2020 7:23:49; update_count: 1; creation_time: 9Sep2020 7:23:49; connection_count: 1; aggregated_log_count: 1; file_count: 1; src: ******; dst: 205.185.216.42; proto: tcp; protocol: HTTP; sig_id: 0; service_id: http; UP_match_table: TABLE_START; ROW_START: 0; match_id: 16; layer_uuid: 9423cebf-45b3-4e4c-b1bb-2e7b7b3dc585; layer_name: EXTERNAL Network; rule_uid: 207e0d97-511c-4d74-865f-f1e736142245; rule_name: ******; ROW_END: 0; ROW_START: 1; match_id: 67108874; layer_uuid: d3d0f35b-398c-43cd-97b3-bf3cf9ab0e17; layer_name: WEB Control Layer; rule_uid: 22e7177c-c98e-4122-80ec-efb94f07ee36; rule_name: ******; ROW_END: 1; UP_match_table: TABLE_END
; UP_action_table: TABL
_START; ROW_START: 0; action: 8; ROW_END: 0; ROW_START: 1; action: 50; ROW_END: 1; UP_action_table: TABLE_END; UP_parent_id_table: TABLE_START; ROW_START: 0; parent_rule: 0; ROW_END: 0; ROW_START: 1; parent_rule: 16; ROW_END: 1; UP_parent_id_table: TABLE_END; aggregated_data_type_table: TABLE_START; ROW_START: 0; data_type_name: Executable File; ROW_END: 0; aggregated_data_type_table: TABLE_END; aggregated_file_table: TABLE_START; ROW_START: 0; file_name: windows-kb890830-x64-v5.83_fede0eab17a3acf1aa945b14f37324ae6a8f6fc6.exe; file_type: Executable; ROW_END: 0; aggregated_file_table: TABLE_END; UP_alert_hll_table: TABLE_START; ROW_START: 0; alert: mail; ROW_END: 0; UP_alert_hll_table: TABLE_END; src_user_name: ******; src_machine_name: ******; user: ******; ProductName: Content Awareness; svc: http; ProductFamily: Network;
Those ****** are me replacing some private data.