Supported Security Events for SIEM

Email Security supports sending these security events to the integrated SIEM platforms.

  • Phishing

  • Suspected Phishing

  • User Reported Phishing

  • Malware

  • Suspected Malware

  • Malicious URL

  • Malicious URL Click

  • DLP

  • Anomaly

  • Shadow IT

  • Spam

  • System Logs (Audit Logs)

Notes:

  • Email Security generates logs for each one of these security events.

  • Email Security does not add sensitive data to the DLP SIEM logs.

  • ERM security events are sent to the SIEM. After activating the ERM feature, the system displays leaked credentials from the past six months, but do not generate security events. Only credentials detected after enabling ERM or starting a POC generate security events of the Anomaly type.