Alerts

Prev Next

To access the Alerts module, click the Alerts link on the main navigation menu. Click on the Inbound and Outbound drop-down menu to change between modes. This page allows you to search for alerts, determine if a malicious email is in quarantine, filter for specific email domains, and domain groups, view information about an individual alert, check the type of threat along with its description, and download the alert reports in CSV format.

ETP_Alerts5.png

To view the details for an individual alert, click the Alert ID link for that alert. A window pops up with the following alert details:

  • Email Summary

  • Hygiene Analysis

  • Quarantine History

  • Alerts and Events

Alerts that have not yet been reviewed are in bold type.

To download the alert reports in CSV format, click the Export to CSV button. A maximum of 10000 alerts can be exported to CSV.

Note

This feature is available for Email Security - Cloud Hygiene users only.

The following table lists the information shown on the Alerts page. You can use the Column drop-down menu to select the columns you want to see.

ETP_AdvThreat2.png

Alert categories

Category description

Alert ID

The ID of the detected malicious email and an alert type icon. Alert types include YARA, Retroactive, QR Code, Riskware, Blocked List Match and Other.

In outbound traffic mode, alert types include Retroactive and Other.

(Alerts having a type other than the ones listed above will be categorised as Other)

Date & Time

Date and time when the alert is initiated for the malicious email.

From

Sender's email address

Recipients

Targeted email addresses

Subject

Malicious email subject

MD5

MD5 hash

URL/Attachment

Malicious URL or name of the malicious attachment file

Email Server

Originating email server that sent the malicious email

Threat Type

Malware group under which the malicious email is classified.

Alerts that belong to no malware group are classified as "Others".

Riskware Rule ID

ID of the riskware rule applied to the alert (This column is not applicable in Outbound traffic mode).

Email Status

Quarantined, scanned, deleted, or, dropped (OOB).

Delivered (retroactive) emails will have status as delivered and dropped (OOB retroactive) emails will have status as dropped (OOB).

Retroactive emails can be identified by the alert icon, Retroactive, on the top-left of the table.

To know more about retroactive statuses, see Retroactive alerts.