A campaign is a set of potentially malicious email messages with similar characteristics. The campaign detection feature groups emails that have similar characteristics, such as the attachment name, subject, or sender. For example, for a campaign that uses an invoice theme references an invoice number in the subject lines and includes a malicious attachment that come from a variety of senders, the Email Security - Server appliance assigns a name to the campaign that is created in the UTC time zone. The campaign name uses the format Campaign[<optional_counter>_<hour><MonthName><day>. The time that is in the campaign name is the time that the first malicious email is received and associated with the campaign. With campaign detection, the amount of data that needs to be analyzed might be significantly reduced while the key characteristics about the email can be maintained by the appliance. A typical campaign can run for three days on the Email Security - Server appliance by default.
You can track the total number of infected emails that are part of a campaign by using the eAlerts > eAlerts > Campaigns page. To view the details about each campaign, see Viewing the campaigns.
This section covers the following information about detecting campaigns: