Available primary search filters

Prev Next

Search filters enable you to define the search criteria and provide more efficient and effective searches from the quarantine database.

The available primary search filter option varies based on the detected item category you have selected. These search filters appear in the View Results section of the detected item category.

Note

Use Columns to display in the View Results section, to select the search filters that you want to view.

Detected Items — Primary search filters

Search filter

Definition

Action taken

Search for an item based on the action that was taken on it. The actions taken by

TSME

are:

  • Clean

  • Cleaned

  • Deleted

  • Deleted Message

  • Denied Access

  • Logged

  • Replaced

  • Rejected

Anti-Virus DAT

Search for an item based on the anti-virus DAT version with a distinctive signature.

To view the current Anti-Virus DAT used, go to DashboardVersions & UpdatesUpdate InformationAnti-Virus Engine | DAT Version | Extra Drivers. For example, the DAT version appears in this format: 6860.0000

Anti-Virus Engine

Search for an item based on the anti-virus engine that had a sequence of characters unique to a virus/unwanted content.

To view the current Anti-Virus Engine used, go to DashboardVersions & UpdatesUpdate InformationAnti-Virus Engine | DAT Version | Extra Drivers. For example, the Anti-Virus Engine version appears in this format: 5400.1158

Banned Phrases

Search by the content of banned phrases that are defined in the DLP and Compliance Rules under Policy ManagerShared ResourceDLP and Compliance Dictionaries.

Detection Name

Search for a detected item based on its name.

File Name

Search by the name of the detected file in the quarantined item.

To view the File Name used, go to Policy ManagerShared ResourceDLP and Compliance DictionariesFile Filtering Rules.

Folder

Search by the folder where quarantined items are stored such as a user's mailbox.

Note

The folder will not be available if the email is quarantined at the On-Access (Transport) level.

Policy Name

Search for an item by a policy name such as a Primary policy or sub-policy that detected the item.

Reason

Search for an item based on the reason why it was detected. This could be based on the scanners and filters such as Anti-Virus, DLP and Compliance, and so on.

Reasons

Search by a rule or rules that were triggered by a particular email. Use this if an item has triggered multiple scanners or filters. For example, if a spam email contains a virus, the Reasons is Anti-Virus.

Recipients

Search for an item through the recipient's email address.

Rule Name

Search for an item based on the rule that triggered one or more scanners/filters. The rule that triggered the scanner or filter is based on the Actions set for each policy.

Scanned by

Search for an item by the scanner name that detected the item.

Sender

Search for an item by the sender's email address.

Server

Search for an item based on the computer name.

State

Search for an item based on its current status. The available items states are:

  • Untrained — Items that are not acted upon such as purged, released, forwarded or deleted. The initial state of all items will be Untrained.

  • Released — Items that are released from the quarantine database.

  • Forwarded — Items that are forwarded to the intended recipients.

Subject

Search for an item based on the subject line of the email message.

Task

Search for an item based on the scan task name which can be an On-Access (Transport) scan task or On-Demand scan task. The on-access scan task that appears in the View Results section is based on the settings you have enabled under Settings & DiagnosticsOn-Access Settings. To know whether the item was detected due to an on-demand scan task, go to DashboardOn-Demand Scans.

Ticket Number

Search for an item based on the ticket number, which is a unique alphanumeric identifier assigned to a specific detection and delivered as a notification through email. It helps identify the associated detection.

TIE Score

Search for items based on the TIE score reputation.