I turned on AMP today and in the mail policy I configured "Messages with File Analysis Pending" to add a custom header which I then notify myself in content filters if that header exists. I've received 15 notifications today which I then was expecting to match up in the File Analysis monitor screen, which has 10 entries, but none of them match up.
In the AMP logs for the e-mails that triggered the pending notification it has entries for "File reputation query initiating" and "Response received for file reputation query from Cloud". For the attachments in the File Analysis monitor screen they have additional entries for "File uploaded for analysis", "Sandbox status event received" and "File Analysis complete".
I have looked all over for the difference but there isn't much detailed information. Does anyone know the difference between AMP file analysis pending and what shows up in File Analysis?