Mappings: Proofpoint Targeted Attack Protection C2C - Message Permitted
Input | Value |
---|---|
Vendor | Proofpoint |
Product | TAP |
Log Format | JSON |
Event ID Regex Pattern | MESSAGE_PERMITTED |
Output | Value |
---|---|
Vendor | Proofpoint |
Product | Targeted Attack Protection |
Record Type |
Cloud SIEM Schema Field | Original Record Key | Notes |
---|---|---|
action | None | The static text MESSAGE_PERMITTED is populated in this schema field. |
email_sender | sender | |
email_subject | subject | |
file_basename | messageParts.filename | |
file_hash_md5 | messageParts.md5 | |
file_hash_sha256 | messageParts.sha256 | |
file_mimeType | messageParts.contentType | |
http_url | threatsInfoMap.1.threat | |
resource | threatsInfoMap.1.threatType | |
srcDevice_ip | senderIP | |
success | None | The static text false is populated in this schema field. |
threat_identifier | threatsInfoMap.1.threatId | |
threat_name | classification | |
threat_referenceUrl | threatsInfoMap.1.threatUrl | |
timestamp | messageTime | We expect the orginal record value of messageTime is in the format yyyy-MM-dd'T'HH:mm:ss.SSSZ |
user_email | recipient | |
user_username | recipient |