On the Search Emails > Processed Emails page, you can view the list of malicious and non-malicious emails that have been processed by the Email Security - Server appliance based on the type of fields (Message ID, Sender, Recipient, Subject Line, URL, and Attachment).
Search entries based on the URLs and attachments were ignored by the Email Security - Server appliance running releases earlier than 8.2.0.
The Processed Emails page also displays the status and state of the scanned emails with an associated verdict based on the results of the scan. You can filter the list of processed emails by Verdict or Status, or both. You can display up to 100 emails per page. You can also export a filtered list of processed emails from the appliance.
If your Email Security - Server appliance is managed by a Central Management System appliance, the results are limited to 500 email records if a search returned more than 500 records on the Processed Emails page. However, you can export records up to a limit of 100 KB.
If an email message body contains a suspicious URL, the Email Security - Server appliance delivers the email while the URL is being analyzed by the Trellix Advanced URL Detection Engine (FAUDE). The Search Emails > Processed Emails page lists the email with the verdict Clean and status Sent or Delivered.
Later, if FAUDE processing detects that the URL is malicious, an alert triggers and the appliance blocks the URL. The event is reflected in the What's Happening panel of the Dashboard, the eAlerts tab, and the Alerts: Email Analysis page. However, the Search Emails > Processed Emails page continues to show the email verdict Clean. The verdict field is not updated with FAUDE results.
The following table describes the processed email fields.
Field | Description |
|---|
Date/Time | The date and time the report is created. |
Appliance | The name of the appliance that processed the email. |
Queue ID | Unique identifier of the message queue. |
Message ID | Unique identifier of the message. |
Sender | Email address of the sender. |
Recipient | Email address of the recipient. |
Subject Line | Text of the subject line of the email. |
URL | Embedded URL that is scanned within an email message body during the selected time period. |
Attachment | Attachment that is scanned within an email message body during the selected time period. |
State | State of the scanned emails: Processing—The email message is in the process of being analyzed by the virtual machine. Processed—The Email Security - Server appliance finished processing the email for all URLs and attachments. Queued for Analysis—URLs and attachments found in the email message are queued for dynamic analysis. The email message is stored in the relevant queue until the analysis is completed. Timed Out—Processing of the email message took longer than the maximum amount of time allowed for email analysis.
|
Verdict | Verdicts associated with the emails: All—Display all associated verdicts. Unknown—Email timed out before analysis could begin. No analysis was performed. Clean—Email was scanned and found to be clean. Malicious—Email was scanned and found to contain a malicious attachment, a malicious URL, or a malicious header.
Bypassed—Email is not scanned because the appliance is filled to capacity and the bypass threshold has been reached. Analysis Timeout—Email was submitted for analysis, but timed out before analysis was complete. The email was only partially analyzed. Blocked Custom Policy—Email was scanned and found to be malicious because it matched entries that you defined in the blocked list or custom YARA rule. Allowed List Policy—Email is not scanned because it matched entries that you defined in the allowed list. Scan Incomplete—Email is not scanned if one or more objects within the email message were not analyzed completely by the appliance. Riskware—Email was scanned if the appliance found a match to a riskware policy rule. Email Size Exceeded—Email is not scanned because the configured email message size limit has been reached. Other—Email is not scanned for some other issue.
|
Status | Action that is taken on the email. All—Display all associated actions. Sent—In Monitor analysis mode or Block analysis mode, the email is delivered to the next-hop destination IP address. Discarded—In Drop analysis mode or Tap/Span analysis mode, the email has been processed and the original email will be discarded. Quarantined—Email has been blocked because an infection was detected. Deferred—In Monitor analysis mode or Block analysis mode, the email cannot be delivered to the next-hop destination IP address. Released—In Block analysis mode, the email is released after it was blocked. The email is delivered to the next-hop destination IP address. Deleted—Email has been deleted from the queue. Rerouted—Email in the queue has been routed to another next-hop destination IP address. Flushed—Email was flushed manually and re-delivered from the deferred queue. ReleaseFailed—The Email Security - Server appliance tried to release the email message to another next-hop but failed, usually due to a delay in the processing flow. You can use this status to verify whether the email is stuck in the queue. QuarantinedFailed—Deleted and quarantined emails are no longer available. Bounced—Email could not be delivered to the next-hop destination IP address and soft bounce is enabled. Purged—Email was in the bounced queue and was permanently removed after the max-bounced-interval expired. Missed—Email was received and the re-written URL was clicked before the detection engine provided a malicious verdict.
|
Signature Names | The name of the alert rule exception that addresses aspects of the same network vulnerability. |
You can view or export the results of processed emails only using the Web UI.
Prerequisites
Administrator or Operator access to the Email Security - Server appliance.
An established connection between your Email Security - Server appliance and the Internet.
The appliance database contains one or more emails that have been processed.