Hi All,
Currently I have TE (R80.20 version) and the management server (R80.30 version). The TE runs MTA with BCC mode. From the management server, I can see the email traffic has copied already to my gateway, but there a lot of logs are generated with the same event. After my short investigation, multiple logs represent the number of recipient. Does Threat Emulation will emulate every single recipient and made it as multiple sessions? or something unusual happens here? Please find below the capture. Thanks for your all kindness.