Skip to content

Latest commit

 

History

History
41 lines (34 loc) · 1.22 KB

4886477c-cc07-4944-9847-ea9380192cf1.md

File metadata and controls

41 lines (34 loc) · 1.22 KB

Mappings: Proofpoint Targeted Attack Protection C2C - Message Permitted

Input Requirements

Input Value
Vendor Proofpoint
Product TAP
Log Format JSON
Event ID Regex Pattern MESSAGE_PERMITTED

Record Output

Output Value
Vendor Proofpoint
Product Targeted Attack Protection
Record Type Email

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
action None The static text MESSAGE_PERMITTED is populated in this schema field.
email_sender sender
email_subject subject
file_basename messageParts.filename
file_hash_md5 messageParts.md5
file_hash_sha256 messageParts.sha256
file_mimeType messageParts.contentType
http_url threatsInfoMap.1.threat
resource threatsInfoMap.1.threatType
srcDevice_ip senderIP
success None The static text false is populated in this schema field.
threat_identifier threatsInfoMap.1.threatId
threat_name classification
threat_referenceUrl threatsInfoMap.1.threatUrl
timestamp messageTime We expect the orginal record value of messageTime is in the format yyyy-MM-dd'T'HH:mm:ss.SSSZ
user_email recipient
user_username recipient