Adding more filters

Prev Next

Searches can be refined based on the evaluation verdicts, message size, attachments, delivery status, and multiple other details. To refine your search, click Add more filters.

Click In or Not In above each field to include or exclude results that match the search.

Note

You can choose one or multiple integration types: SMTP, MS365 API, or Google Workspace API. The selected integration type affects the options available for some filters. If none or all are selected, all options for the filters will be shown.

Filter

Description

Advanced threat engine configuration

The email search can be performed based on advanced threat engine configuration. The choices are Allowed URLs, Allowed Attachment Hashes, Blocked URLs, or Blocked Attachment Hashes.

Advanced threat verdict

The email search can be performed based on Advanced Threat verdict. Choices are Pass or Fail.

Attachment MD5/SHA 256

Search for emails based on attachment MD5/SHA256 hashes. You can specify a maximum of 10 comma separated values.

Attachment name

Search for emails based on attachment names. You can specify a maximum of 10 comma separated values.

Custom rule name

Search for emails based on custom rule names. You can specify a maximum of 10 comma separated vales.

Domain groups

The domain groups drop down provides options for limiting the domain groups in the searches, multiple domain groups can be selected for refined searches in email trace.

DLP Classification

Search for outbound emails based on Trellix Data Loss Prevention Network Prevent classifications. You can specify a maximum of 10 comma separated values.

DLP Policy Action

The email search can be performed based on the Email Security - Cloud actions implemented as per the Trellix Data Loss Prevention Network Prevent policy configuration. For more information, see DLP policy.

DLP Rule Name

Search for outbound emails based on Trellix Data Loss Prevention Network Prevent rule names. You can specify a maximum of 10 comma separated values.

Domains

The domains drop down provides options for limiting the domains in the searches, multiple domains can be selected for refined searches in email trace.

Email Campaign ID

Search for emails grouped together under a campaign based on similar characteristics, such as URLs, subject, or sender.

End user reported emails

The email search can be performed based on end user reported emails specified as Junk, Phishing, or Others.

File types

Search for emails based on attachment file types. You can specify a maximum of 10 comma separated values.

Has attachment

The email search can be performed based on attachments. The search will be limited to emails that contain attachments.

Has malicious QR

The email search can be performed based on malicious QRs. The search will be limited to emails that contain malicious QRs.

Has retroactive alert

The email search can be performed based on retroactive alerts. The search will be limited to emails that have generated retroactive alerts.

Message size range

The email search can be performed based on the message size, and the values in KB for specifying the minimum and maximum size of the email message.

Policy action

The email search can be performed based on Policy Action based on custom rule matches.

For SMTP the choices are Drop, Quarantine, or Others.

For MS365 API and Google Workspace API, the choices are Remediate or Others.

Rejection reason

If a status of Rejected was selected in the previous field, you can select one or more reasons.

For SMTP, the reasons include recipient Rejected, Downstream MTA not responsive, Routing loop detected, DHAP match, and so on .

For MS365 API and Google Workspace API, you can select one or both reasons: Email size over Max Limit or Rate limit exceeded.

Remediation action

The email search can be performed based on whether a remediation policy quarantined, moved, monitored, or deleted a message, or if the policy action failed. You can select all filters to search for.

For MS365 API and Google Workspace API, the email search can also be performed based on whether a remediation policy released a message or if the release failed.

Riskware rules

The email search can be performed based on riskware rules. Select a rule or select Select All.

Sender IP

Search for emails based on IP addresses. You can specify a maximum of 10 comma separated values.

Searching by Sender IP is available for SMTP only.

Spam verdict

The email search can be performed based on Spam verdict. Choices are Pass or Fail.

Status

This field provides search option based on the status of the email. The search field has a drop down menu with multiple statuses for email flow including the email delivered, quarantined or failures, rejections. You can select more than one status.

For the searches with rejection status further refined search criteria can be defined with Rejection Reason filter.

Deleted, Delivered, Dropped, Dropped (OOB), Permanent Failure, Quarantined, Split, and Temporary Failure are available for SMTP only.

Scan Bypassed and Scan are available for MS365 API and Google Workspace API only.

Tag

The email search can be performed based on remediation, impersonation, or URL click reporting tags. The choices are Auto, Manual and Native Remediation, Impersonation, URL Clicked Blocked, URL Clicked Before Malicious Classification, Released, Spam Levels - Low, Medium and High.

Select Notification tag to receive notifications about alerts, alert summaries, digest emails, end users, dashboard reports, rate limiting and Outlook add-in (FPFN).

Select the Encrypted Attachment tag to find emails that contain password-protected attachments and quarantined under riskware rule ID 65066.

Native Remediation is also available for MS365 API and Google Workspace API.

For more information about remediation policies, see Managing remediation policies. For more information about impersonation, see Message analysis policies. For more information about URL click reporting, see Advanced threat alert details.

URL domain

Search for emails based on URL domains. You can specify a maximum of 10 comma separated values.

The search uses exact match. You must use the full domain name, including the subdomains and not including the http or https protocol. 'www.example.com' and 'example.com' are considered different domains.

Virus verdict

The email search can be performed based on Virus verdict. Choices are Pass or Fail.

YARA rule action

The email search can be performed based on YARA Rule Actions. Choices are Alert and Quarantine, Alert Only, Monitor, or No Match.

  • Alert and Quarantine: matches Block/Quarantine

  • Alert Only: matches monitor and alert

  • Monitor: matches monitor only

  • No match: matches any YARA non-matches