New search
From this section you can search and view scan results of all messages passed through the appliance. You can also save common search filters in order to speed up the search process later.
General filters
From the first part of the page you can set general email searching information such as:
- Subject (the email subject)
- Email (the recipient or sender email address or domain)
- Date Range (the approximate period when the email landed on the appliance)
- Type (the scanning result category of the message such as Threat, Clean or SMTP Reject)
Additional Filters
From this section you can set advanced and more accurate filters in order to find all the emails matching the characteristics you are looking for.
You can concatenate more filters using the plus button placed on the right of each filter set. This filters are concatenated with a logic AND operator.
You can define more search conditions creating two filters with the OR blue button. If a message matches at least a filter set, it will be displayed as result.
Search results
When the Search button is clicked, the appliance will search and display all messages matching the filters previously set.
For each message you can perform the following operations:
- Export (export selected results in common formats such as PDF, CSV ecc…)
- Recall (recall the delivered message from the user’s inbox if a threat remediation connector is set)
- Rescan (put the message in the scanning queue of the appliance aiming to get a different scanning result, in case of changed appliance settings)
- Release (deliver the message to the next hop without any modification by ESG)
- Delete (completely remove the message from the appliance)
- Mark as (this message will be learned by the bayesian engine as good or bad)
- Submit as (submit the message, as good in case of false positive or bad in case of false negative, to LibraCyber Labs to further analysis)
For each message is displayed following information:
- Date (the date when the message landed on ESG)
- Sender (the email address of the sender)
- Recipients (the list of recipient addresses)
- Subject (the email subject)
- Result (the scanning result, learn more)
- Delivery (if the message has been delivered to the next hop, stopped or deleted)
Note: by clicking on the green eye icon placed at the end of each result you can consult the message detail page, as explained below.
Understanding messages direction
For each messages we also know if the message is incoming email flow or outgoing email flow. The direction is displayed with a special arrow icon at end of the message record.
Incoming: light blue arrow pointing the bottom of the page
Outgoing: green arrow pointing the top of the page
In the image below, the first is an Outgoing message, the latter is an Incoming message
Message detail
By clicking on the green eye button placed at the end of each result, is shown the message detail page.
The message detail page has a general email data section and 5 additional sections containing advanced information.
This page is documented in the Message detail documentation page.
Saved searches
The saved searches tab is documented under the Reports documentation page.