Email analysis timeout

Prev Next

Administrators can use either the Web UI or the CLI to configure the maximum amount of time (between 1 and 90 minutes) to allow an email message to be processed before analysis on the email times out and the email is delivered. This feature is enabled by default and the default timeout period is 60 minutes. The lower the timeout period value is, the higher the possibility of analysis timing out on the email messages, resulting in detection loss. If enabled, X-headers can be appended to the email so administrators can locally manage the timed-out emails.

When analysis of an email takes longer than the configured number of minutes, the state of that email on the Search Emails > Processed Emails page changes to "Timed Out" and the email message is released to the recipient without further analysis. However, if the Email Security - Server appliance detects any malicious indicators before analysis times out, then the email message is processed based on how you configured the Email Security - Server appliance to handle malicious emails.

If both the X-header and the advanced X-header are enabled, then the Email Security - Server appliance adds a "x-FireEye: Scan Incomplete" label to the X-header of each email that times out. You can enable X-headers by using the email-analysis policy xheader enable command and you can enable advanced X-headers by using the email-analysis policy xheader advancedxheader enable command.

The new timeout period value takes effect for all new emails as soon as you apply the change. However, any email messages that were already undergoing analysis when you changed the timeout period value will continue being processed with the old timeout period value.

Prerequisites

  • Administrator or Operator access to the Email Security - Server appliance.