Viewing the retroactive detection details in the Web UI

Prev Next

In the Alerts page of the Email Security - Server appliance, you can drill down to identify the matched URLs and hashes that are detected as malicious in the email message of a generated retroactive detection alert, grouped by recipient, sender, or alert. In the eAlerts page of the Email Security - Server appliance, you can drill down to identify the matched URLs and hashes detected as malicious for a malware event of a generated retroactive detection alert.

When Advanced URL Defense is enabled on the Email Security - Server appliance, the malicious URLs that include LIVE.DTI.URL as the name of the malware type (malicious, exploit, or phish) detected by the DTI Cloud are categorized and tracked as individual alerts in the grouping on the eAlerts page and Alerts Details page.

Note

When the Central Management System appliance manages Email Security - Server and Network Security appliances, the Central Management System appliance correlates the Email Security - Server retroactive detection alerts with the Network Security alerts. For details about Email Security - Server and Network Security event correlation, see the "Reviewing Email Alerts Correlated with Web Events" section in the "Monitoring Aggregated Alert Data" chapter of the Central Management System Administration Guide.

Prerequisites

  • Administrator, Monitor, or Analyst, access to the Email Security - Server appliance

  • A CONTENT_UPDATES license for security content updates

  • A two-way sharing CONTENT_UPDATES license (if Advanced URL Defense is enabled)