Files
2021-08-18 16:56:31 +00:00

25 lines
742 B
YAML

name: Get Email Info
id: bc91a8cf-35e7-4bb2-8140-e756cc06fd75
version: 1
date: '2017-11-09'
author: Bhavin Patel, Splunk
type: Investigation
datamodel: []
description: This search returns all the information Splunk might have collected a
specific email message over the last 2 hours.
search: '| from datamodel Email.All_Email | search message_id=$message_id$'
how_to_implement: To successfully implement this search you must be ingesting your
email logs or capturing unencrypted network traffic which contains email communications.
known_false_positives: ''
references: []
tags:
analytic_story:
- Brand Monitoring
- Suspicious Emails
product:
- Splunk Phantom
required_fields:
- _time
- message
security_domain: network