Custom Queries
Email Security stores the metadata of all items (emails, files, user logins, etc.) obtained through the public APIs of the protected cloud applications and inspected by the system.
-
For harmless items, metadata is retained for two weeks.
-
For malicious items, metadata is stored indefinitely.
Custom Queries provides direct access to the metadata database, and you can use them to:
-
Troubleshoot
-
Build custom reports
-
Perform bulk action such as quarantining phishing emails
Managing Custom Queries
The Analytics Queries page shows a list of all custom queries in your environment.
To view the Analytics Queries page, click Analytics > Custom Queries.

Query Table
| Column | Description |
|---|---|
| SaaS |
Logo of the SaaS application. |
| Status |
Status of the query.
|
| Name |
Displays the name of the query. Click on the query name to view the related query results. |
| Description | Description related to the query. |
| Matched | Number of matched query results. |
| Entity Type | Type of entity. |
|
Severity |
Severity level of the query.
|
|
Create |
The date and time when the alert was created. |
|
Created By |
The email address of the user who created the query. |
Acting on Queries
-
To create a new query, see Creating and Saving a New Query.
- To filter query results, see Filtering the Query Results.
-
To remove queries, select the required queries and click Remove Selected.
In the Remove Queries pop-up that appears, click OK.
-
To import query details, select the required queries and click Import a Query in the top-right corner.
-
To export query details, select the required queries and click Export Selected in the top right corner.