AT Alert (Email Security — Cloud Edition)
- Published on Aug 25, 2026
Prev Next Note
Every AT alert generates a separate CEF notification.
CEF:0|Trellix|ETP|3.0|etp|malicious email|10|rt=Nov 07 2016 23:27:17 UTC
suser=yser@abc.com duser=usera@xyz.pqr.com fname=test.zip
fileHash=ca9424e92816332d8bb60a45e4ec29e9 destinationDnsDomain=xyz.pqr.com
externalId=9999999 cs1Label=sname cs1=Malware.archive cs3Label=Subject
cs3=Arc Sight Test CEF cs4Label=Link
cs4=https://etp.trellixcloud.com/alert/9999999/ cs5Label=Client cs5=AAAA
Was this article helpful?
Related articles
Central Management System (CMS) > Central Management System System Administration Guide Release 11.x > Appendices
Helix Enterprise > Helix Enterprise TQL Reference Guide Release 2023.1 > TQL cheatsheet and use cases
Helix > Trellix Helix TQL Reference Guide > TQL cheatsheet and use cases
Network Security (NX) > Common Security Platform Product Docs > API Reference Release 2025.1 > Endpoints > Retrieving ATI details