The metadata streaming feature on the appliance allows you to export your email metadata (such as recipient, subject line, attachment information, and URLs) into designated receivers for external analysis. Supported receivers are HTTP, Rsyslog, and Trellix Helix Enterprise.
HTTP metadata receivers require a server URL as a destination. If authentication is needed, you can choose a basic or token method.
Rsyslog metadata receivers require an IPv4 address or fully qualified domain name entered as a destination. You can choose to use an SSL, TCP, or UDP network protocol for securing your connections and have metadata streamed in Berkeley Software Distribution (BSD), Internet Engineering Task Force (IETF), or System iNtrusion Analysis and Reporting Environment (SNARE) formats.
Metadata is streamed from the appliance to the HTTP or rsyslog receiver event by event and is extracted in JSON format only.
You can configure HTTP and rsyslog receivers for metadata streaming on the appliance using both the Web UI and CLI commands.
Note
For information about email metadata streaming to Helix Enterprise, see the Helix Integration Guide.