Corelight_v2_smtp_CL

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index


Attribute Value
Custom Log V1 Yes 🔶 — uses type-suffixed column names
Ingestion API Supported ✓ Yes

Contents

Schema (33 columns)

Source: KQL validation test schema

Column Name Type
_path_s string
_system_name_s string
_write_ts_t datetime
cc_s string
date_s string
domains_s string
first_received_s string
from_s string
fuids_s string
helo_s string
id_orig_h_s string
id_orig_p_d real
id_resp_h_s string
id_resp_p_d real
in_reply_to_s string
is_webmail_b bool
last_reply_s string
mailfrom_s string
msg_id_s string
path_s string
rcptto_s string
reply_to_s string
second_received_s string
subject_s string
TimeGenerated datetime
tls_b bool
to_s string
trans_depth_d real
ts_t datetime
uid_s string
urls_s string
user_agent_s string
x_originating_ip_s string

Solutions (1)

This table is used by the following solutions:

Connectors (1)

This table is ingested by the following connectors:

Connector Selection Criteria
Corelight Connector Exporter

Content Items Using This Table (5)

Analytic Rules (1)

In solution Corelight:

Analytic Rule Selection Criteria
Corelight - SMTP Email containing NON Ascii Characters within the Subject

Hunting Queries (1)

In solution Corelight:

Hunting Query Selection Criteria
Corelight - Abnormal Email Subject

Workbooks (3)

In solution Corelight:

Workbook Selection Criteria
Corelight_Alert_Aggregations
Corelight_Data_Explorer
Corelight_Security_Workflow

Parsers Using This Table (1)

Other Parsers (1)

Parser Solution Selection Criteria
corelight_smtp Corelight

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index