You can enable or disable an advanced X-header feature by using the Email Security - Server appliance CLI.
When you enable the advanced X-header feature, the Email Security - Server appliance does the following
Inserts the X-header "Scan Incomplete" line if one or more objects within the email message was not analyzed completely.
When this feature is disabled, the Email Security - Server appliance inserts the X-header "Clean" line. The Email Security - Server appliance does not insert the X-header "Scan Incomplete" line if the email message contained a malicious attachment. When the Email Security - Server appliance identifies a scan as incomplete, the output of the
show submission idcommand shows the submission status asfailed,ae_start_failed,dnld_couldnt_resolve_host,dnld_couldnt_connect,dnld_operation_timedout,dnld_other,dnld_http_returned_error,dnld_too_many_redirects, orfile_not_found.Inserts the X-Hheader "X-FireEye: Riskware Block" line in copy of email message when the Email Security - Server appliance is in monitor analysis mode.
Inserts the X-header "X-FireEye: Riskware Match" line when analysis found a matched riskware policy rule.
The advanced X-header feature is disabled by default.
Important
Emails that are tagged "X-Trellix: Scan Incomplete" are marked with the verdict "Clean" on the Search Emails > Processed Emails page in the Web UI.
Prerequisites
Administrator or Operator access to the Email Security - Server appliance.
Verify that the Email Security - Server appliance is deployed in Block analysis mode or Monitor analysis mode. Use the
show email-analysiscommand. For details about how to configure Block analysis mode or Monitor analysis mode, see Configuring the analysis mode using the Web UI or Configuring the analysis mode using the CLI.Enable the X-header feature if it is disabled. Use the
show email-analysis policycommand. For details about how to enable the X-header feature, see Enabling or disabling the X-header using the Web UI or Enabling or disabling the X-header using the CLI.