03-07-2024 07:04 AM
I'm looking to essentially create a dictionary of specific domains, that will be used by a content-filter that checks the "Envelope Sender" for a term in the content dictionary, and if it matches to added a CEF Log Entry that can be picked up by our SIEM.
Unsure of what the correct format should be, this is what I have currently:
@domain\.com$
Is there a better way to test this rather than waiting for the next email to come from this domain and see if it matches? I've tried to understand the Trace function, however I'm not sure where I would see the if the domain matched or not. When I do my test trace, I can see that its going to our default policy for content filters where the one I created sits, but I cant see whether it matched or not.
Solved! Go to Solution.
03-07-2024 07:43 AM
03-07-2024 07:43 AM
03-12-2024 09:41 AM
Thanks, all working now using the above syntax!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide