Skip to main content
Skip table of contents

V 2.0 : Content Security Event

Vendor Documentation

Classification

Rule Name

Rule Type

Classification

Common Event

V 2.0 : Content Security EventBase RuleOther SecurityGeneral Security
V 2.0 : Content Security : UnknownSub RuleActivityGeneral Threat Message
V 2.0 : Content Security : Not ApplicableSub RuleOther SecurityGeneral Security
V 2.0 : Content Security : CleanSub RuleFailed ActivityThreat Deleted
V 2.0 : Content Security : DeleteSub RuleFailed ActivityThreat Deleted
V 2.0 : Content Security : MoveSub RuleActivityGeneral Threat Message
V 2.0 : Content Security : RenameSub RuleActivityGeneral Threat Message
V 2.0 : Content Security : Pass/LogSub RuleActivityGeneral Threat Message
V 2.0 : Content Security : StripSub RuleFailed ActivityThreat Deleted
V 2.0 : Content Security : DropSub RuleFailed ActivityThreat Blocked
V 2.0 : Content Security : QuarantineSub RuleActivityQuarantine
V 2.0 : Content Security : Insert/ReplaceSub RuleActivityGeneral Threat Message
V 2.0 : Content Security : ArchiveSub RuleActivityGeneral Threat Message
V 2.0 : Content Security : StampSub RuleActivityGeneral Threat Message
V 2.0 : Content Security : BlockSub RuleFailed ActivityThreat Blocked
V 2.0 : Content Security : Redirect Mail For ApprovalSub RuleActivityGeneral Threat Message
V 2.0 : Content Security : EncryptSub RuleActivityGeneral Threat Message
V 2.0 : Content Security : DetectSub RuleActivityGeneral Threat Message
V 2.0 : Content Security : ResetSub RuleFailed ActivityThreat Blocked

Mapping with LogRhythm Schema

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
Header (logVer)N/AN/ACEF format version
Header (vendor)N/AN/AAppliance vendor
Header (pname)N/A N/AAppliance product
Header (pver) N/AN/AAppliance product version
Header (eventid)<vmid>Text/StringMS: Filter action
Header (eventName)N/AN/APolicy name
Header (severity)N/AN/ASeverity
cntN/AN/ANumber of detections
deviceExternalIdN/AN/AID
rtN/AN/ALog generation time in UTC
dhost<recipient>Text/String/NumberList of all recipients
duserN/AN/AOne of the recipients
act<action>
<tag1>
NumberFilter action
cs1LabelN/AN/ACorresponding label for the "cs1" field
cs1N/AN/APolicy settings
cs2LabelN/AN/ACorresponding label for the "cs2" field
cs2N/AN/AProduct version
cs3LabelN/AN/ACorresponding label for the "cs3" field
cs3N/AN/AFilter type
0: Unknown
1: ContentFilter
2: AttachmentFilter
3: StandardFilter
4: SizeFilter
5: DisclaimerMgr
6: SpamFilter
7: OPP
8: ImportFilter
9: PhishingFilter
10: UrlReputationFilter
cs4LabelN/AN/ACorresponding label for the "cs4" field
cs4N/AN/AReason Code
cs5LabelN/AN/ACorresponding label for the "cs5" field
cs5N/AN/AReason code source
cs6LabelN/AN/ACorresponding label for the "cs6" field
cs6N/AN/AAction
0: Unknown
1: N/A
2: Deliver
3: Delete
4: Quarantine
5: Postpone
6: Forward
7: Replace
8: Archive
100: Strip
101: Pass
catN/AN/ALog type
dvchost<dname>Text/String/NumberEndpoint host name
cn1LabelN/AN/ACorresponding label for the "cn1" field
cn1<severity>NumberSeverity code
0: Unknown
1: Information
2: Warning
3: Error
4: Critical
TMCMLogSeverityN/AN/ADescription of severity
fname<object>Text/String/NumberFile
msg<subject>Text/String/NumberSubject
shost<sender>Text/String/NumberList of all senders/users in violation
suserN/AN/AOne of the senders/users in violation
request<url>Text/String/NumberSuspicious URL
cn2LabelN/AN/ACorresponding label for the "cn2" field
cn2N/AN/AFilter action result
deviceFacilityN/AN/AProduct
src<sip>IP AddressEmail sender IP address
reason<reason>Text/StringCritical threat type
A: Known Advanced Persistent Threat (APT)
B: Social engineering attack
C: Vulnerability attack
D: Lateral movement
E: Unknown threats
F: C&C callback
G: Ransomware
filepathN/AN/ASuspicious file location
ApexCentralHostN/AN/AApex Central host name
devicePayloadIdN/AN/AUnique message GUID
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.