Corelight_v3_smtp_CL

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Tables Index


Attribute Value
Ingestion API Supported ✓ Yes

Contents

Schema (33 columns)

Source: KQL validation test schema

Column Name Type
cc dynamic
domains dynamic
email_to dynamic
first_received string
from string
fuids dynamic
helo string
id_orig_h string
id_orig_p int
id_resp_h string
id_resp_p int
in_reply_to string
is_webmail bool
last_reply string
log_date string
mailfrom string
msg_id string
path string
rcptto dynamic
reply_to string
second_received string
subject string
system_name string
TimeGenerated datetime
tls bool
trans_depth long
ts datetime
Type string
uid string
urls dynamic
user_agent string
write_ts datetime
x_originating_ip string

Schema References

Official Microsoft Learn documentation for field/column information:

Solutions (1)

This table is used by the following solutions:

Connectors (1)

This table is ingested by the following connectors:

Connector Selection Criteria
Corelight Connector Exporter

Content Items Using This Table (4)

Analytic Rules (1)

In solution Corelight:

Analytic Rule Selection Criteria
Corelight - SMTP Email containing NON Ascii Characters within the Subject

Hunting Queries (1)

In solution Corelight:

Hunting Query Selection Criteria
Corelight - Abnormal Email Subject

Workbooks (2)

In solution Corelight:

Workbook Selection Criteria
Corelight_Data_Explorer
Corelight_Security_Workflow

Parsers Using This Table (1)

Other Parsers (1)

Parser Solution Selection Criteria
corelight_smtp Corelight

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Tables Index