Title
Page icon
Create new category
Edit page index title
Edit category
Edit link
Events
The Events page provides a detailed log of MetaDefender Cloud Email Security ™ processing history and incidents, including their severity, status, and verdict. This guide explains how to use this page effectively for monitoring and managing security events.
Search and Filtering Options
Search Bar: Allows users to search for specific events based on keywords.
Time Range: Narrows down events by time range.
Export: The following content can be exported to CSV format (Max 10 000 entries):
Event ID
Date/Time
Status
Policy
Direction
Affected Users
Verdict
Sender
Recipients
From
To
Cc
Subject
Message-ID
Size
Filters: Use the panel to narrow the list of events using one or more search criteria. It includes:
Status: Filters events by their current processing status (for example, Delivered or Quarantined).
Direction: Filters events by email direction (Inbound, Outbound, or Internal).
Verdict: Filters events by the final processing verdict.
Detected By: Filters events based on the detection engine or technology that identified the threat.
Sanitized File Type: Filters events containing sanitized files of a specific file type.
Not Sanitized File Type: Filters events containing files that were not sanitized.
Sanitized Object Type: Filters events by the type of object removed or reconstructed during sanitization (for example, Macro or Hyperlink).
Message ID: Searches for a specific email message using its unique Message ID.
Subject: Filters events by the email subject.
SMTP Sender: Filters events by the SMTP envelope sender address.
From Address: Filters events by the email sender shown in the From header.
Recipient: Filters events by the recipient email address.
Policy Name: Filters events processed by a specific policy.
Attachment Name: Filters events containing attachments with a specified file name.
Threat Name: Filters events by the malware or threat name reported by the detection engine.
Origin Country: Filters events based on the detected country of origin.
Origin City: Filters events based on the detected city of origin.
Filter Actions:
Apply: Applies the selected filter criteria and updates the event list.
Clear: Removes all selected filter criteria and restores the default view.
Column visibility: Configure columns to display in list. Available are:
Time of Event (Fixed Column): Displays the date and time the event occurred. This column is fixed and cannot be hidden.
Status: Shows the current processing status of the event (for example, Delivered or Quarantined).
From: Displays the email sender.
Affected User: Shows the recipient or user affected by the event.
Details: Displays a summary of the event, such as the email subject or other identifying information.
Policy: Shows the policy that was applied during email processing.
Verdict: Displays the final security verdict assigned to the event.
Labels: Shows message classifications and labels, such as spam or category indicators.
Direction: Displays the email flow direction (Inbound, Outbound).
Event ID: Displays the unique identifier assigned to the event.
Event List
Each row in the event list represents an event with the following details:
Time of Event: Timestamp indicating when the event occurred.
Event ID: Unique identifier assigned to each security event.
Status: The current status of the event:
Quarantined: Quarantined content.
Delivered: Delivered content.
Investigating: Issue under investigation.
Released: Released content.
Delete: Delete content.
Closed: Issue closed without any action.
Policy: Indicates the Policy that applied for the the content.
Direction: Indicates email direction (inbound/outbound).
Affected User: The user impacted by the event.
Details: A brief description of the email content or subject.
Verdict: See Verdicts.
Viewing Event details
The Event Overview page provides detailed information about an individual email event, including message metadata, processing results, applied labels, associated content, and available administrative actions. It allows administrators to investigate email activity, review processed attachments, and perform actions such as releasing or deleting quarantined messages.
Depending on the event verdict and status, different actions and information may be available.
Event Summary
The Event section provides a high-level overview of how the email was processed.
It includes:
Time of Event: Date and time the email was processed.
Processing Time: Total time required to analyze the message.
Policy: Policy applied during processing.
Direction: Email flow direction (Inbound, Outbound, or Internal).
Verdict: Final processing result.
Common verdicts include:
Sanitized
Malicious
Invalid File Structure
Other verdicts based on the applied security policy.
Administrative Actions
The available actions depend on the event status and verdict.
Possible actions include:
Release: Releases a quarantined email to the intended recipient.
Delete: Permanently deletes the quarantined email.
Release Original: Releases the original version of a sanitized email.
Delete Original: Deletes the original version while retaining the sanitized copy.
Actions: Displays additional event-specific operations.
Labels
The Labels section displays classifications assigned during message analysis.
Examples include:
SCL (Spam Confidence Level)
BCL (Bulk Complaint Level)
SFV (Spam Filtering Verdict)
CAT (Category)
Attachments
These labels provide additional context about spam filtering and message classification performed by the email platform.
Asset Details
The Asset Details section contains metadata about the processed email.
Information includes:
Message Information
Item Type
Affected User
Status
Sent At
Received At
Quarantine ID
Message ID
Message Size
Email Details
Subject
To
From
CC
SMTP Sender
SMTP Recipients
Received From
The Status field reflects the current state of the email, for example:
Delivered
Quarantined
Other workflow-specific statuses.
Asset Actions
Additional actions are available from the Asset Details section.
View
The View menu provides access to additional message information.
Available options may vary depending on the event and deployment.
Download Email
Downloads the original email in .eml format for offline analysis.
This option is available only when the original email is retained.
Audit History
Opens the audit log for the selected event, displaying administrative actions performed on the email, such as quarantine, release, or deletion. Also allows adding custom comments.
Content
The Content section lists every file extracted from the email, including message bodies and attachments.
Each row represents a processed object.
The table includes:
File Name
Detection
Prevention
Category
File Type
File Size
Scanned
Use the search box to locate files by:
File name
File type
File category
Detection
Displays the antivirus detection summary for each file.
Examples include:
0/15 – No antivirus engines detected a threat.
1/7 – One antivirus engine detected the file as malicious.
Selecting the detection value opens the Event Details page for that file.
Prevention
Displays the Content Disarm and Reconstruction (CDR) result for each file.
Possible values include:
Sanitized
Not Sanitized
Selecting the prevention status opens the file's Prevention details.
Category
Displays the detected file category.
Examples include:
Text
Image
Audio or Video Format
Document
File Type
Displays the detected file format.
Examples include:
ASCII Text
Hypertext Markup Language
Windows Media Audio
Portable Network Graphics
Navigation
Selecting a file from the Content table opens the corresponding Content Details page, where you can review:
File metadata
Antivirus engine results
AI analysis
Content Disarm and Reconstruction (CDR) details
This allows administrators to investigate individual files without leaving the event workflow.
Content Details
The Content Details page provides comprehensive information about a scanned email attachment or file, including scan results, detection verdicts, prevention outcomes, and file metadata. It allows administrators to investigate why a file was flagged, review individual antivirus engine results, examine sanitization outcomes, and export scan information.
The page is organized into three tabs:
Overview – Summary of scan and file information.
Detection – Detailed antivirus and AI detection results.
Prevention – Content Disarm and Reconstruction (CDR) sanitization results.
The page also includes the following actions:
Report Incorrect Detection: Submit a false positive or false negative report for review.
Download as JSON: Export the complete scan results in JSON format.
Overview
The Overview tab provides a high-level summary of the scan results together with detailed file information.
Scan Results
Advanced Threat Detection
Displays the antivirus scan summary.
It includes:
Detection Count: Number of antivirus engines that detected the file as malicious (for example, 1/6).
Detection Status: Indicates whether threats were detected.
Selecting the widget opens the Detection tab.
Zero-Day Malware Prevention
Displays the Content Disarm and Reconstruction (CDR) result.
Possible statuses include:
Sanitized – The file was successfully sanitized.
Not Sanitized – The file could not be sanitized or did not meet sanitization requirements.
Selecting the widget opens the Prevention tab.
File Details
Displays technical information about the scanned file.
Information includes:
Category: General file category (for example, Audio or Video Format, Text).
File Type: Detected file format.
File Extension
File Size
Scan Timestamp
Scan Duration
MD5 Hash
SHA1 Hash
SHA256 Hash
These values can be used for investigation, threat hunting, or cross-referencing with external security tools.
Detection
The Detection tab provides detailed results from every antivirus engine that analyzed the file.
OPSWAT Predictive AI
Displays the verdict from OPSWAT's AI-powered malware analysis.
Possible results include:
No Threats Found
AI-generated detection verdicts when applicable
This section provides an additional layer of analysis beyond traditional antivirus engines.
Advanced Threat Detection
Summarizes the overall antivirus detection results.
It includes:
Detection Ratio: Number of engines detecting the file as malicious.
Total Engines Scanned
Example:
1/6 antivirus engines detected a threat
0/14 antivirus engines detected no threats
Antivirus Engine Results
Lists the verdict returned by each antivirus engine.
Each row displays:
Engine: Antivirus engine used during scanning.
Verdict: Detection result returned by the engine.
Definition Update: Signature database version or update timestamp used during the scan.
Prevention
The Prevention tab displays the results of Content Disarm and Reconstruction (CDR) processing.
Zero-Day Malware Prevention
Shows the number of objects requiring sanitization.
Possible results include:
Objects Sanitized – One or more active objects were successfully removed or reconstructed.
No Objects Required Sanitization – The file contained no active content requiring sanitization.
Sanitization Details
When sanitization is performed, this table lists every object that was modified.
Information includes:
SHA256: Hash of the processed object.
Type: Object type (for example, Macro, Hyperlink, Embedded Object, Script).
Redaction: Indicates whether the object was removed or reconstructed.
Sanitization Details: Additional information describing the performed action.
Use the search field to locate a specific object by its SHA256 hash.
Navigation
The tabs provide progressively more detailed information about the scanned file:
Overview provides a summary of the scan results and file metadata.
Detection displays detailed AI and antivirus engine verdicts.
Prevention displays Content Disarm and Reconstruction (CDR) results and any sanitized objects.
The Report Incorrect Detection and Download as JSON actions are available from every tab, allowing administrators to report suspected false detections or export the complete event data for further analysis.