CiscoEmailSecurity Deprecated
Deprecated. Use Cisco Security Management Appliance instead.
Network Security · Cisco Email Security (Beta) (Deprecated)
Details
| ID | CiscoEmailSecurity |
|---|---|
| Provider | Cisco Systems |
| Category | Network Security |
| From Version | 5.0.0 |
| Docker Image | demisto/python3:3.10.8.37753 |
| Supported Modules | Agentix |
README
Cisco Email Security is an email security gateway . It detects and blocks a wide variety of email-borne threats, such as malware, spam and phishing.
This integration was integrated and tested with version 13 of CiscoEmailSecurity
Configure CiscoEmailSecurity in Cortex
| Parameter | Description | Required |
|---|---|---|
| base_url | Server URL (e.g. https://192.168.0.1) | True |
| credentials | API Username | True |
| insecure | Trust any certificate (not secure) | False |
| proxy | Use system proxy settings | False |
| timeout | request timeout | False |
Commands
You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.
cisco-email-security-report-get
Retrieves details of an email security report by counter type.
Base Command
cisco-email-security-report-get
Input
| Argument Name | Description | Required |
|---|---|---|
| start_date | Start datetime for the search, in the following format: YYYY-MM-DD hh:mm:ss. The seconds must be 00, due to an API limitation. | Required |
| end_date | End datetime for the search, in the following format: YYYY-MM-DD hh:mm:ss. The seconds must be 00, due to an API limitation. | Required |
| counter | Fetch data from a specific counter. Possible values are “reporting_system”, “mail_incoming_traffic_summary”, “mail_vof_threat_summary”, “mail_vof_specific_threat_summary”, and “mail_amp_threat_summary”. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| CiscoEmailSecurity.Report.MailAmpThreatSummary.incoming_malicious | Number | The number of incoming malicious messages. |
| CiscoEmailSecurity.Report.MailAmpThreatSummary.outgoing_malicious | Number | The number of outgoing malicious messages. |
| CiscoEmailSecurity.Report.MailVofSpecificThreatSummary.threat_detected_virus_or_malware | Number | The number of the messages identified as a virus or malware. |
| CiscoEmailSecurity.Report.MailVofThreatSummary.threat_detected | Number | The total number of messages identified as a threat. |
| CiscoEmailSecurity.Report.ReportingSystem.heartbeat | Number | The reporting system heartbeat. |
| CiscoEmailSecurity.Report.ReportingSystem.end_time | String | The reporting end time. |
| CiscoEmailSecurity.Report.ReportingSystem.begin_time | String | The reporting start time. |
| CiscoEmailSecurity.Report.ReportingSystem.centralized_reporting_expired | Number | The number of messages that centralized reporting expired. |
| CiscoEmailSecurity.Report.ReportingSystem.centralized_reporting_enabled | Number | The number of messages that centralized reporting enabled. |
| CiscoEmailSecurity.Report.MailIncomingTrafficSummary.blocked_dmarc | Number | The number of blocked dmarc messages. |
| CiscoEmailSecurity.Report.MailIncomingTrafficSummary.blocked_invalid_recipient | Number | The number of blocked invalid recipient messages. |
| CiscoEmailSecurity.Report.MailIncomingTrafficSummary.blocked_reputation | Number | The number of blocked reputation messages. |
| CiscoEmailSecurity.Report.MailIncomingTrafficSummary.bulk_mail | Number | The number of bulk mail messages. |
| CiscoEmailSecurity.Report.MailIncomingTrafficSummary.detected_amp | Number | The number of detected amp messages. |
| CiscoEmailSecurity.Report.MailIncomingTrafficSummary.detected_spam | Number | The number of detected spam messages. |
| CiscoEmailSecurity.Report.MailIncomingTrafficSummary.detected_virus | Number | The number of detected virus messages. |
| CiscoEmailSecurity.Report.MailIncomingTrafficSummary.malicious_url | Number | The number of malicious URL messages. |
| CiscoEmailSecurity.Report.MailIncomingTrafficSummary.marketing_mail | Number | The number of blocked dmarc messages. |
| CiscoEmailSecurity.Report.MailIncomingTrafficSummary.social_mail | Number | The number of marketing mail messages. |
| CiscoEmailSecurity.Report.MailIncomingTrafficSummary.threat_content_filter | Number | The number of threat content filter messages. |
| CiscoEmailSecurity.Report.MailIncomingTrafficSummary.total_clean_recipients | Number | The total number of clean recipients. |
| CiscoEmailSecurity.Report.MailIncomingTrafficSummary.total_graymail_recipients | Number | The total number of graymail recipients. |
| CiscoEmailSecurity.Report.MailIncomingTrafficSummary.total_recipients | Number | The tota number of recipients. |
| CiscoEmailSecurity.Report.MailIncomingTrafficSummary.total_threat_recipients | Number | The total number of threat recipients. |
| CiscoEmailSecurity.Report.MailIncomingTrafficSummary.verif_decrypt_fail | Number | The number of verif decrypt fail messages. |
| CiscoEmailSecurity.Report.MailIncomingTrafficSummary.verif_decrypt_success | Number | The number of verif decrypt success messages. |
| CiscoEmailSecurity.Report.MailIncomingTrafficSummary.detected_spam_suspect | Number | The number of suspected spam messages. |
| CiscoEmailSecurity.Report.MailIncomingTrafficSummary.detected_spam_certain | Number | The number of certain spam certain messages. |
| CiscoEmailSecurity.Report.MailIncomingTrafficSummary.failed_spf | Number | The number of failed spf messages. |
| CiscoEmailSecurity.Report.MailIncomingTrafficSummary.failed_dkim | Number | The number of failed dkim messages. |
| CiscoEmailSecurity.Report.MailIncomingTrafficSummary.total_spoofed_emails | Number | The total number of spoofed email messages. |
| CiscoEmailSecurity.Report.MailIncomingTrafficSummary.total_mailbox_auto_remediated_recipients | Number | The total number of mailbox auto-remediated recipients. |
| CiscoEmailSecurity.Report.MailIncomingTrafficSummary.detected_virus_per_msg | Number | The number of detected virus per msg messages. |
| CiscoEmailSecurity.Report.MailIncomingTrafficSummary.ims_spam_increment_over_case | Number | The number of ims spam increment over case messages. |
cisco-email-security-messages-search
Executes a search for messages in Cisco Email Security.
Base Command
cisco-email-security-messages-search
Input
| Argument Name | Description | Required |
|---|---|---|
| start_date | Start datetime for the search, in the following format: YYYY-MM-DD hh:mm:ss. The seconds must be 00, due to an API limitation. | Required |
| end_date | End datetime for the search, in the following format: YYYY-MM-DD hh:mm:ss. The seconds must be 00, due to an API limitation. | Required |
| limit | The maximum number of records to retrieve. If you set a limit you should also use an offset. |
Optional |
| offset | Specify an offset value to retrieve a subset of records starting with the offset value. If you use an offset you should also set a retrieval limit. |
Optional |
| attachment_name_operator | Attachment name operator to filter by. If you want to use attachment, you need to pass the following arguments: attachment_name_operator and attachment_name_value. Possible values are: “is”, “begins_with”, and “contains”. |
Optional |
| attachment_name_value | Attachment name value to filter by. If you want to use attachment, you need to pass the following arguments: attachment_name_operator and attachment_name_value. |
Optional |
| file_hash | File SHA256 hash to filter by. | Optional |
| recipient_filter_operator | Recipient filter operator to filter by. If you want to use recipient, you need to pass the following arguments: recipient_filter_operator and recipient_filter_value. Possible values are: “is”, “begins_with”, and “contains”. |
Optional |
| recipient_filter_value | Recipient filter value to filter with. If you want to use recipient, you need to pass the following arguments: recipient_filter_operator and recipient_filter_value. |
Optional |
| sender_filter_operator | Sender filter operator to filter with. If you want to use sender, you need to pass the following arguments: sender_filter_operator and sender_filter_value. Possible values are: “is”, “begins_with”, and “contains”. |
Optional |
| sender_filter_value | Sender filter value to filter by. If you want to use sender, you need to pass the following arguments: sender_filter_operator and sender_filter_value. |
Optional |
| subject_filter_operator | Subject filter operator to filter by If you want to use subject, you need to pass the following arguments: subject_filter_operator and subject_filter_value. Possible values are: “is”, “begins_with”, and “contains”. |
Optional |
| subject_filter_value | Subject filter value to filter by. If you want to use subject, you need to pass the following arguments: subject_filter_operator and subject_filter_value. |
Optional |
| message_id | Message ID to filter with | Optional |
| cisco_message_id | Cisco message ID to filter by. | Optional |
| sender_ip | Sender IP address to filter by. | Optional |
| message_direction | Message direction to filter by. Possible values are “incoming” and “outgoing”. | Optional |
| spam_positive | Whether to filter by positive spam positive. Possible values are: “True” and “False”. | Optional |
| quarantined_as_spam | Whether to filter by in spam quarantine. Possible values: are “True” and “False”. | Optional |
| quarantine_status | Quarantine status to filter. Possible values are: “POLICY”, “AMP”, “AV”, “UNCLASSIFIED”, “DLP”, and “OUTBREAK”. | Optional |
| url_reputation | URL reputation to filter by. Possible values are: “Malicious” and “Suspicious”. | Optional |
| virus_positive | Virus positive to filter by. Possible values are: “True” and “False”. | Optional |
| domain_name_operator | Domain name operator to filter by. If you want to use domain filter, you need to pass the following arguments: domain_name_operator and domain_name_value. Possible values are: “is”, “begins_with”, and “contains”. |
Optional |
| domain_name_value | Domain name value to filter by. If you want to use domain filter, you need to pass the following arguments: domain_name_operator and domain_name_value. |
Optional |
| contained_malicious_urls | Whether to filter by contained malicious URLs. Possible values are: “True” and “False”. | Optional |
| contained_neutral_urls | Whether to filter by is contained natural URLs. Possible values are: “True” and “False”. | Optional |
| macro_file_types_detected | Macro file types detected to filter by. temlate of macro_file_types_detected - Microsoft%20Office%20Files,Adobe%20Portable%20Document%20Format |
Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| CiscoEmailSecurity.Messages.attributes.direction | String | The message direction. |
| CiscoEmailSecurity.Messages.attributes.hostName | String | The message hostName. |
| CiscoEmailSecurity.Messages.attributes.icid | Number | The message injection connection ID. |
| CiscoEmailSecurity.Messages.attributes.isCompleteData | Boolean | Whether all data is in the message. |
| CiscoEmailSecurity.Messages.attributes.mailPolicy | String | The message mail policy. |
| CiscoEmailSecurity.Messages.attributes.messageStatus | String | The status of the message. |
| CiscoEmailSecurity.Messages.attributes.mid | Number | The message ID. |
| CiscoEmailSecurity.Messages.attributes.recipient | String | The recipient of the message. |
| CiscoEmailSecurity.Messages.attributes.replyTo | String | Who the message is in reply to. |
| CiscoEmailSecurity.Messages.attributes.sbrs | String | The message sender base score. |
| CiscoEmailSecurity.Messages.attributes.sender | String | The message sender. |
| CiscoEmailSecurity.Messages.attributes.senderDomain | String | The message sender domain. |
| CiscoEmailSecurity.Messages.attributes.senderGroup | String | The message sender group. |
| CiscoEmailSecurity.Messages.attributes.senderIp | String | The message sender IP address. |
| CiscoEmailSecurity.Messages.attributes.serialNumber | String | The message serial number. |
| CiscoEmailSecurity.Messages.attributes.subject | String | The message subject. |
| CiscoEmailSecurity.Messages.attributes.timestamp | String | The message datetime. |
| CiscoEmailSecurity.Messages.attributes.verdictChart | String | The message verdict chart. |
cisco-email-security-message-details-get
Retrieves details of a message.
Base Command
cisco-email-security-message-details-get
Input
| Argument Name | Description | Required |
|---|---|---|
| start_date | Start datetime for the search, in the following format: YYYY-MM-DD hh:mm:ss. The seconds must be 00, due to an API limitation. | Required |
| end_date | End datetime for the search, in the following format: YYYY-MM-DD hh:mm:ss. The seconds must be 00, due to an API limitation. | Required |
| cisco_id | Cisco message ID to filter with. | Required |
| message_id | Message ID to filter with. | Required |
| appliance_serial_number | Appliance serial number to filter with. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| CiscoEmailSecurity.Message.attachments | String | The attachments of the message. |
| CiscoEmailSecurity.Message.direction | String | The message direction. |
| CiscoEmailSecurity.Message.hostName | String | The message host name. |
| CiscoEmailSecurity.Message.isCompleteData | Number | Is there in the message all the data. |
| CiscoEmailSecurity.Message.mailPolicy | String | The message mail policy. |
| CiscoEmailSecurity.Message.messageSize | String | The size of the message. |
| CiscoEmailSecurity.Message.messageStatus | String | The status of the message. |
| CiscoEmailSecurity.Message.mid | Number | Message ID. |
| CiscoEmailSecurity.Message.midHeader | String | The header message ID of the message. |
| CiscoEmailSecurity.Message.recipient | String | The recipient of the message. |
| CiscoEmailSecurity.Message.sender | String | The sender of the message. |
| CiscoEmailSecurity.Message.senderGroup | String | The sender group of the message. |
| CiscoEmailSecurity.Message.sendingHostSummary.ipAddress | String | The IP address of the host message. |
| CiscoEmailSecurity.Message.sendingHostSummary.reverseDnsHostname | String | The dns host name of the message. |
| CiscoEmailSecurity.Message.sendingHostSummary.sbrsScore | String | The sender base score host of the message. |
| CiscoEmailSecurity.Message.showAMP | Boolean | Is the AMP shown. |
| CiscoEmailSecurity.Message.showDLP | Boolean | Wheter the DLP is shown. |
| CiscoEmailSecurity.Message.showSummaryTimeBox | Boolean | Whether the summary time box is shown. |
| CiscoEmailSecurity.Message.showURL | Boolean | Whether the URL is shown. |
| CiscoEmailSecurity.Message.smtpAuthId | String | The SMTP auth ID of the message. |
| CiscoEmailSecurity.Message.subject | String | The message date subject. |
| CiscoEmailSecurity.Message.summary.description | String | The message summary description. |
| CiscoEmailSecurity.Message.summary.lastEvent | Number | The message summary last event. |
| CiscoEmailSecurity.Message.summary.timestamp | String | The message summary timestamp. |
| CiscoEmailSecurity.Message.timestamp | String | The message timestamp. |
cisco-email-security-spam-quarantine-search
Executes a search for spam quarantine.
Base Command
cisco-email-security-spam-quarantine-search
Input
| Argument Name | Description | Required |
|---|---|---|
| start_date | Start datetime for the search, in the following format: YYYY-MM-DD hh:mm:ss. The seconds must be 00, due to an API limitation. | Required |
| end_date | End datetime for the search, in the following format: YYYY-MM-DD hh:mm:ss. The seconds must be 00, due to an API limitation. | Required |
| limit | Specify the number of records to retrieve. If you use a limit you should also use a offset. |
Optional |
| offset | Specify an offset value to retrieve a subset of records starting with the offset value. If you use an offset you should also set a retrieval limit. |
Optional |
| order_by_from_address | From address to filter by. | Optional |
| order_by_to_address | To address to filter by. | Optional |
| order_by_subject | Subject to filter by | Optional |
| order_dir_from_address | From address order to filter by. Possible values are: “asc” and “desc”. | Optional |
| order_dir_to_address | To address order to filter by. Possible values are: “asc” and “desc”. | Optional |
| order_dir_subject | Subject order to filter by. Possible values are: “asc” and “desc”. | Optional |
| recipient_value | Recipient value to filter by. | Optional |
| recipient_operator | Recipient operator to filter by. Possible values are: “is”, “begins_with”, and “contains”. | Optional |
| filter_value | Filter value to filter by. | Optional |
| filter_operator | Filter operator to filter by. Possible values are: “is”, “begins_with”, and “contains”. | Optional |
Context Output
There is no context output for this command.
cisco-email-security-spam-quarantine-message-details-get
Retrieves details for a quarantined message.
Base Command
cisco-email-security-spam-quarantine-message-details-get
Input
| Argument Name | Description | Required |
|---|---|---|
| message_id | Message ID to filter by. | Required |
Context Output
There is no context output for this command.
cisco-email-security-dlp-details-get
Retrieves details on a DLP.
Base Command
cisco-email-security-dlp-details-get
Input
| Argument Name | Description | Required |
|---|---|---|
| start_date | Start datetime for the search, in the following format: YYYY-MM-DD hh:mm:ss. The seconds must be 00, due to an API limitation. | Required |
| end_date | End datetime for the search, in the following format: YYYY-MM-DD hh:mm:ss. The seconds must be 00, due to an API limitation. | Required |
| cisco_id | Cisco message ID to filter by. | Required |
| message_id | Message ID to filter by. | Required |
| appliance_serial_number | Appliance serial number to filter by. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| CiscoEmailSecurity.DLP.attachments | String | The attachments of the DLP. |
| CiscoEmailSecurity.DLP.direction | String | The DLP direction. |
| CiscoEmailSecurity.DLP.dlpDetails.dlpMatchedContent.messagePart | String | The message part of the DLP details. |
| CiscoEmailSecurity.DLP.dlpDetails.dlpMatchedContent.messagePartMatch.classifier | String | The classifier of the DLP details. |
| CiscoEmailSecurity.DLP.dlpDetails.dlpMatchedContent.messagePartMatch.classifierMatch | String | The classifier match of the DLP details. |
| CiscoEmailSecurity.DLP.dlpDetails.dlpPolicy | String | The DLP policy. |
| CiscoEmailSecurity.DLP.dlpDetails.mid | String | The message ID of the DLP details. |
| CiscoEmailSecurity.DLP.dlpDetails.riskFactor | Number | The risk factor of the DLP. |
| CiscoEmailSecurity.DLP.dlpDetails.violationSeverity | String | The violation severity of the DLP. |
| CiscoEmailSecurity.DLP.hostName | String | The host name of the DLP. |
| CiscoEmailSecurity.DLP.messageSize | String | The message size of the DLP. |
| CiscoEmailSecurity.DLP.mid | Number | The message ID of the DLP. |
| CiscoEmailSecurity.DLP.midHeader | String | The header message ID of the DLP. |
| CiscoEmailSecurity.DLP.recipient | String | The recipient of the DLP. |
| CiscoEmailSecurity.DLP.sender | String | The sender of the DLP. |
| CiscoEmailSecurity.DLP.senderGroup | String | The sender group of the DLP. |
| CiscoEmailSecurity.DLP.sendingHostSummary.ipAddress | String | The IP address of the host DLP. |
| CiscoEmailSecurity.DLP.sendingHostSummary.reverseDnsHostname | String | The DNS host name of the DLP. |
| CiscoEmailSecurity.DLP.sendingHostSummary.sbrsScore | String | The sender base score host of the DLP. |
| CiscoEmailSecurity.DLP.showDLPDetails | Boolean | Whether the DLP details are shown. |
| CiscoEmailSecurity.DLP.smtpAuthId | String | The SMTP auth ID of the DLP. |
| CiscoEmailSecurity.DLP.subject | String | The subject of the DLP. |
| CiscoEmailSecurity.DLP.timestamp | String | The datetime of the DLP. |
cisco-email-security-amp-details-get
Retrieves details of an AMP.
Base Command
cisco-email-security-amp-details-get
Input
| Argument Name | Description | Required |
|---|---|---|
| start_date | Start datetime for the search, in the following format: YYYY-MM-DD hh:mm:ss. The seconds must be 00, due to an API limitation. | Required |
| end_date | End datetime for the search, in the following format: YYYY-MM-DD hh:mm:ss. The seconds must be 00, due to an API limitation. | Required |
| cisco_id | Cisco message ID to filter by. | Required |
| message_id | Message ID to filter by. | Required |
| appliance_serial_number | Appliance serial number to filter by. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| CiscoEmailSecurity.AMP.ampDetails.description | String | The description of the AMP. |
| CiscoEmailSecurity.AMP.ampDetails.lastEvent | Boolean | Whether this is the last event of the AMP. |
| CiscoEmailSecurity.AMP.ampDetails.timestamp | String | The datetime of the AMP. |
| CiscoEmailSecurity.AMP.attachments | String | The attachments of the AMP. |
| CiscoEmailSecurity.AMP.direction | String | The direction of the AMP. |
| CiscoEmailSecurity.AMP.hostName | String | The hostname of the AMP. |
| CiscoEmailSecurity.AMP.messageSize | String | The message size of the AMP. |
| CiscoEmailSecurity.AMP.mid | Number | The message ID of the AMP. |
| CiscoEmailSecurity.AMP.midHeader | String | The header message ID of the AMP. |
| CiscoEmailSecurity.AMP.recipient | String | The recipient of the AMP. |
| CiscoEmailSecurity.AMP.sender | String | The sender of the AMP. |
| CiscoEmailSecurity.AMP.senderGroup | String | The sender group of the AMP. |
| CiscoEmailSecurity.AMP.sendingHostSummary.ipAddress | String | The IP address of the host AMP. |
| CiscoEmailSecurity.AMP.sendingHostSummary.reverseDnsHostname | String | The DNS hostname of the AMP. |
| CiscoEmailSecurity.AMP.sendingHostSummary.sbrsScore | String | The sender base score host of the AMP. |
| CiscoEmailSecurity.AMP.showAMPDetails | Boolean | Whether AMP details are shown. |
| CiscoEmailSecurity.AMP.smtpAuthId | String | The SMTP auth ID of the AMP. |
| CiscoEmailSecurity.AMP.subject | String | The subject of the AMP. |
| CiscoEmailSecurity.AMP.timestamp | String | The datetime of the AMP. |
cisco-email-security-url-details-get
Retrieves details of a URL.
Base Command
cisco-email-security-url-details-get
Input
| Argument Name | Description | Required |
|---|---|---|
| start_date | Start datetime for the search, in the following format: YYYY-MM-DD hh:mm:ss. The seconds must be 00, due to an API limitation. | Required |
| end_date | End datetime for the search, in the following format: YYYY-MM-DD hh:mm:ss. The seconds must be 00, due to an API limitation. | Required |
| cisco_id | Cisco message ID to filter by. | Required |
| message_id | Message ID to filter by. | Required |
| appliance_serial_number | Appliance serial number to filter by. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| CiscoEmailSecurity.URL.attachments | String | The attachments of the URL. |
| CiscoEmailSecurity.URL.direction | String | The direction of the URL. |
| CiscoEmailSecurity.URL.hostName | String | The hostName of the URL. |
| CiscoEmailSecurity.URL.mid | Number | The message ID of the URL. |
| CiscoEmailSecurity.URL.midHeader | String | The header message ID of the URL. |
| CiscoEmailSecurity.URL.recipient | String | The recipient of the URL. |
| CiscoEmailSecurity.URL.sdrAge | String | The software defined radio age of the URL. |
| CiscoEmailSecurity.URL.sdrCategory | String | The software defined radio category of the URL. |
| CiscoEmailSecurity.URL.sdrReputation | String | The software defined radio reputation of the URL. |
| CiscoEmailSecurity.URL.sender | String | The URL of the sender. |
| CiscoEmailSecurity.URL.senderGroup | String | The sender group of the URL. |
| CiscoEmailSecurity.URL.sendingHostSummary.ipAddress | String | The IP address of the host URL. |
| CiscoEmailSecurity.URL.sendingHostSummary.reverseDnsHostname | String | The DNS host name of the URL. |
| CiscoEmailSecurity.URL.sendingHostSummary.sbrsScore | String | The sender base score host of the URL. |
| CiscoEmailSecurity.URL.showURLDetails | Boolean | Whether the URL details are shown. |
| CiscoEmailSecurity.URL.smtpAuthId | String | The SMTP auth ID of the URL. |
| CiscoEmailSecurity.URL.subject | String | The URL subject. |
| CiscoEmailSecurity.URL.urlDetails.description | String | The description of the URL. |
| CiscoEmailSecurity.URL.urlDetails.lastEvent | Boolean | Whether this is the last event of the URL. |
| CiscoEmailSecurity.URL.urlDetails.timestamp | String | The datetime of the URL details. |
cisco-email-security-spam-quarantine-messages-delete
Deletes quarantined messages.
Base Command
cisco-email-security-spam-quarantine-messages-delete
Input
| Argument Name | Description | Required |
|---|---|---|
| messages_ids | A list of ID’s to delete, comma separated. | Required |
Context Output
There is no context output for this command.
cisco-email-security-spam-quarantine-messages-release
Releases quarantined messages.
Base Command
cisco-email-security-spam-quarantine-messages-release
Input
| Argument Name | Description | Required |
|---|---|---|
| messages_ids | A comma-separated list of IDs to release. | Required |
Context Output
There is no context output for this command.
cisco-email-security-list-entries-get
Retrieves a list of entries.
Base Command
cisco-email-security-list-entries-get
Input
| Argument Name | Description | Required |
|---|---|---|
| list_type | List type to filter by. Possible values are: “safelist” and “blocklist”. | Required |
| limit | Specify an offset value to retrieve a subset of records starting with the offset value. If you use an offset you should also set a retrieval limit. |
Optional |
| offset | Specify an offset value to retrieve a subset of records starting with the offset value. If you use a offset you should also use a limit. |
Optional |
| view_by | View by sender or recipient. | Required |
| order_by | How to order the results. Possible values are: “sender” and “recipient”. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| CiscoEmailSecurity.ListEntries.Safelist.senderList | String | The safelist sender list. |
| CiscoEmailSecurity.ListEntries.Safelist.recipientAddresses | String | The safelist recipient addresses. |
| CiscoEmailSecurity.ListEntries.Safelist.recipientList | String | The safelist recipient list. |
| CiscoEmailSecurity.ListEntries.Safelist.senderAddresses | Number | The safelist sender addresses. |
| CiscoEmailSecurity.ListEntries.Blocklist.senderList | String | The block list sender list. |
| CiscoEmailSecurity.ListEntries.Blocklist.recipientAddresses | String | The block list recipient addresses. |
| CiscoEmailSecurity.ListEntries.Blocklist.recipientList | String | The block list recipient list. |
| CiscoEmailSecurity.ListEntries.Blocklist.senderAddresses | Number | The bloc klist sender addresses. |
cisco-email-security-list-entry-add
Performs actions on list entries. Supports add, edit, and append.
Base Command
cisco-email-security-list-entry-add
Input
| Argument Name | Description | Required |
|---|---|---|
| list_type | List type. Possible values are: “safelist” and “blocklist”. | Required |
| action | Select the action to perform on the list. Possible values are: “add”, “edit”, and “append”. | Required |
| recipient_addresses | A comma-separated list of recipient addresses on which to perform the action. separated) | Optional |
| recipient_list | A comma-separated list of recipient lists on which to perform the action. | Optional |
| sender_addresses | A comma-separated list of sender addresses on which to perform the action. | Optional |
| sender_list | A comma-separated list of sender lists on which to perform the action. | Optional |
| view_by | View by “sender” or “recipient”. | Required |
Context Output
There is no context output for this command.
cisco-email-security-list-entry-delete
Deletes a list entry.
Base Command
cisco-email-security-list-entry-delete
Input
| Argument Name | Description | Required |
|---|---|---|
| list_type | List type | Required |
| recipient_list | A comma-separated list of recipient lists to delete. | Optional |
| sender_list | A comma-seaprated list of sender lists to delete. | Optional |
| view_by | View by “sender” or “recipient”. | Required |
Context Output
There is no context output for this command.
Configuration parameters
base_url— Server URL (e.g. https://192.168.0.1) (required)credentials— API Username (required)insecure— Trust any certificate (not secure)proxy— Use system proxy settingstimeout— Request Timeout
Commands (13)
-
cisco-email-security-amp-details-getRetrieves details of an AMP.
-
cisco-email-security-dlp-details-getRetrieves details on a DLP.
-
cisco-email-security-list-entries-getRetrieves a list of entries.
-
cisco-email-security-list-entry-addPerforms actions on list entries. Supports add, edit, and append.
-
cisco-email-security-list-entry-deleteDeletes a list entry.
-
cisco-email-security-message-details-getRetrieves details of a message.
-
cisco-email-security-messages-searchExecutes a search for messages in Cisco Email Security.
-
cisco-email-security-report-getRetrieves details of an email security report by counter type.
-
cisco-email-security-spam-quarantine-message-details-getRetrieves details for a quarantined message.
-
cisco-email-security-spam-quarantine-messages-deleteDeletes quarantined messages.
-
cisco-email-security-spam-quarantine-messages-releaseReleases quarantined messages.
-
cisco-email-security-spam-quarantine-searchExecutes a search for spam quarantine.
-
cisco-email-security-url-details-getRetrieves details of a URL.
category: Network Security provider: Cisco Systems commonfields: id: CiscoEmailSecurity version: -1 configuration: - display: Server URL (e.g. https://192.168.0.1) name: base_url required: true type: 0 - display: API Username name: credentials required: true type: 9 - display: Trust any certificate (not secure) name: insecure type: 8 required: false - display: Use system proxy settings name: proxy type: 8 required: false - defaultvalue: '2000' display: Request Timeout name: timeout type: 0 required: false description: Deprecated. Use Cisco Security Management Appliance instead. display: CiscoEmailSecurity (Beta) (Deprecated) name: CiscoEmailSecurity script: commands: - arguments: - description: 'Start datetime for the search, in the following format: YYYY-MM-DD hh:mm:ss. The minutes and the seconds must be 00, due to an API limitation.' name: start_date required: true - description: 'End datetime for the search, in the following format: YYYY-MM-DD hh:mm:ss. The minutes and the seconds must be 00, due to an API limitation.' name: end_date required: true - auto: PREDEFINED description: Fetch data from a specific counter. Possible values are "reporting_system", "mail_incoming_traffic_summary", "mail_vof_threat_summary", "mail_vof_specific_threat_summary", and "mail_amp_threat_summary". name: counter predefined: - reporting_system - mail_incoming_traffic_summary - mail_vof_threat_summary - mail_vof_specific_threat_summary - mail_amp_threat_summary required: true - defaultValue: Hosted_Cluster description: Cisco device group name name: device_group_name description: Retrieves details of an email security report by counter type. name: cisco-email-security-report-get outputs: - contextPath: CiscoEmailSecurity.Report.MailAmpThreatSummary.incoming_malicious description: The number of incoming malicious messages. type: Number - contextPath: CiscoEmailSecurity.Report.MailAmpThreatSummary.outgoing_malicious description: The number of outgoing malicious messages. type: Number - contextPath: CiscoEmailSecurity.Report.MailVofSpecificThreatSummary.threat_detected_virus_or_malware description: The number of the messages identified as a virus or malware. type: Number - contextPath: CiscoEmailSecurity.Report.MailVofThreatSummary.threat_detected description: The total number of messages identified as a threat. type: Number - contextPath: CiscoEmailSecurity.Report.ReportingSystem.heartbeat description: The reporting system heartbeat. type: Number - contextPath: CiscoEmailSecurity.Report.ReportingSystem.end_time description: The reporting end time. type: String - contextPath: CiscoEmailSecurity.Report.ReportingSystem.begin_time description: The reporting start time. type: String - contextPath: CiscoEmailSecurity.Report.ReportingSystem.centralized_reporting_expired description: The number of messages that centralized reporting expired. type: Number - contextPath: CiscoEmailSecurity.Report.ReportingSystem.centralized_reporting_enabled description: The number of messages that centralized reporting enabled. type: Number - contextPath: CiscoEmailSecurity.Report.MailIncomingTrafficSummary.blocked_dmarc description: The number of blocked dmarc messages. type: Number - contextPath: CiscoEmailSecurity.Report.MailIncomingTrafficSummary.blocked_invalid_recipient description: The number of blocked invalid recipient messages. type: Number - contextPath: CiscoEmailSecurity.Report.MailIncomingTrafficSummary.blocked_reputation description: The number of blocked reputation messages. type: Number - contextPath: CiscoEmailSecurity.Report.MailIncomingTrafficSummary.bulk_mail description: The number of bulk mail messages. type: Number - contextPath: CiscoEmailSecurity.Report.MailIncomingTrafficSummary.detected_amp description: The number of detected amp messages. type: Number - contextPath: CiscoEmailSecurity.Report.MailIncomingTrafficSummary.detected_spam description: The number of detected spam messages. type: Number - contextPath: CiscoEmailSecurity.Report.MailIncomingTrafficSummary.detected_virus description: The number of detected virus messages. type: Number - contextPath: CiscoEmailSecurity.Report.MailIncomingTrafficSummary.malicious_url description: The number of malicious URL messages. type: Number - contextPath: CiscoEmailSecurity.Report.MailIncomingTrafficSummary.marketing_mail description: The number of blocked dmarc messages. type: Number - contextPath: CiscoEmailSecurity.Report.MailIncomingTrafficSummary.social_mail description: The number of marketing mail messages. type: Number - contextPath: CiscoEmailSecurity.Report.MailIncomingTrafficSummary.threat_content_filter description: The number of threat content filter messages. type: Number - contextPath: CiscoEmailSecurity.Report.MailIncomingTrafficSummary.total_clean_recipients description: The total number of clean recipients. type: Number - contextPath: CiscoEmailSecurity.Report.MailIncomingTrafficSummary.total_graymail_recipients description: The total number of graymail recipients. type: Number - contextPath: CiscoEmailSecurity.Report.MailIncomingTrafficSummary.total_recipients description: The tota number of recipients. type: Number - contextPath: CiscoEmailSecurity.Report.MailIncomingTrafficSummary.total_threat_recipients description: The total number of threat recipients. type: Number - contextPath: CiscoEmailSecurity.Report.MailIncomingTrafficSummary.verif_decrypt_fail description: The number of verif decrypt fail messages. type: Number - contextPath: CiscoEmailSecurity.Report.MailIncomingTrafficSummary.verif_decrypt_success description: The number of verif decrypt success messages. type: Number - contextPath: CiscoEmailSecurity.Report.MailIncomingTrafficSummary.detected_spam_suspect description: The number of suspected spam messages. type: Number - contextPath: CiscoEmailSecurity.Report.MailIncomingTrafficSummary.detected_spam_certain description: The number of certain spam certain messages. type: Number - contextPath: CiscoEmailSecurity.Report.MailIncomingTrafficSummary.failed_spf description: The number of failed spf messages. type: Number - contextPath: CiscoEmailSecurity.Report.MailIncomingTrafficSummary.failed_dkim description: The number of failed dkim messages. type: Number - contextPath: CiscoEmailSecurity.Report.MailIncomingTrafficSummary.total_spoofed_emails description: The total number of spoofed email messages. type: Number - contextPath: CiscoEmailSecurity.Report.MailIncomingTrafficSummary.total_mailbox_auto_remediated_recipients description: The total number of mailbox auto-remediated recipients. type: Number - contextPath: CiscoEmailSecurity.Report.MailIncomingTrafficSummary.detected_virus_per_msg description: The number of detected virus per msg messages. type: Number - contextPath: CiscoEmailSecurity.Report.MailIncomingTrafficSummary.ims_spam_increment_over_case description: The number of ims spam increment over case messages. type: Number - arguments: - description: 'Start datetime for the search, in the following format: YYYY-MM-DD hh:mm:ss. The seconds must be 00, due to an API limitation.' name: start_date required: true - description: 'End datetime for the search, in the following format: YYYY-MM-DD hh:mm:ss. The seconds must be 00, due to an API limitation.' name: end_date required: true - description: |- The maximum number of records to retrieve. If you set a limit you should also use an offset. name: limit - description: |- Specify an offset value to retrieve a subset of records starting with the offset value. If you use an offset you should also set a retrieval limit. name: offset - auto: PREDEFINED description: |- Attachment name operator to filter by. If you want to use attachment, you need to pass the following arguments: attachment_name_operator and attachment_name_value. Possible values are: "is", "begins_with", and "contains". name: attachment_name_operator predefined: - is - begins_with - contains - description: |- Attachment name value to filter by. If you want to use attachment, you need to pass the following arguments: attachment_name_operator and attachment_name_value. name: attachment_name_value - description: File SHA256 hash to filter by. name: file_hash - auto: PREDEFINED description: |- Recipient filter operator to filter by. If you want to use recipient, you need to pass the following arguments: recipient_filter_operator and recipient_filter_value. Possible values are: "is", "begins_with", and "contains". name: recipient_filter_operator predefined: - is - begins_with - "contains\t" - description: |- Recipient filter value to filter with. If you want to use recipient, you need to pass the following arguments: recipient_filter_operator and recipient_filter_value. name: recipient_filter_value - auto: PREDEFINED description: |- Sender filter operator to filter with. If you want to use sender, you need to pass the following arguments: sender_filter_operator and sender_filter_value. Possible values are: "is", "begins_with", and "contains". name: sender_filter_operator predefined: - is - begins_with - contains - description: |- Sender filter value to filter by. If you want to use sender, you need to pass the following arguments: sender_filter_operator and sender_filter_value. name: sender_filter_value - auto: PREDEFINED description: |- Subject filter operator to filter by If you want to use subject, you need to pass the following arguments: subject_filter_operator and subject_filter_value. Possible values are: "is", "begins_with", and "contains". name: subject_filter_operator predefined: - is - begins_with - contains - description: |- Subject filter value to filter by. If you want to use subject, you need to pass the following arguments: subject_filter_operator and subject_filter_value. name: subject_filter_value - description: Message ID to filter with name: message_id - description: Cisco message ID to filter by. name: cisco_message_id - description: Sender IP address to filter by. name: sender_ip - auto: PREDEFINED description: Message direction to filter by. Possible values are "incoming" and "outgoing". name: message_direction predefined: - incoming - outgoing - auto: PREDEFINED description: 'Whether to filter by positive spam positive. Possible values are: "True" and "False".' name: spam_positive predefined: - 'True' - 'False' - auto: PREDEFINED description: 'Whether to filter by in spam quarantine. Possible values: are "True" and "False".' name: quarantined_as_spam predefined: - 'True' - 'False' - auto: PREDEFINED description: 'Quarantine status to filter. Possible values are: "POLICY", "AMP", "AV", "UNCLASSIFIED", "DLP", and "OUTBREAK".' name: quarantine_status predefined: - POLICY - AMP - AV - UNCLASSIFIED - DLP - OUTBREAK - auto: PREDEFINED description: 'URL reputation to filter by. Possible values are: "Malicious" and "Suspicious".' name: url_reputation predefined: - Malicious - Suspicious - auto: PREDEFINED description: 'Virus positive to filter by. Possible values are: "True" and "False".' name: virus_positive predefined: - 'True' - 'False' - auto: PREDEFINED description: |- Domain name operator to filter by. If you want to use domain filter, you need to pass the following arguments: domain_name_operator and domain_name_value. Possible values are: "is", "begins_with", and "contains". name: domain_name_operator predefined: - is - begins_with - contains - description: |- Domain name value to filter by. If you want to use domain filter, you need to pass the following arguments: domain_name_operator and domain_name_value. name: domain_name_value - auto: PREDEFINED description: 'Whether to filter by contained malicious URLs. Possible values are: "True" and "False".' name: contained_malicious_urls predefined: - 'True' - 'False' - auto: PREDEFINED description: 'Whether to filter by is contained natural URLs. Possible values are: "True" and "False".' name: contained_neutral_urls predefined: - 'True' - 'False' - description: | Macro file types detected to filter by. temlate of macro_file_types_detected - Microsoft%20Office%20Files,Adobe%20Portable%20Document%20Format name: macro_file_types_detected description: Executes a search for messages in Cisco Email Security. name: cisco-email-security-messages-search outputs: - contextPath: CiscoEmailSecurity.Messages.attributes.direction description: The message direction. type: String - contextPath: CiscoEmailSecurity.Messages.attributes.hostName description: The message hostName. type: String - contextPath: CiscoEmailSecurity.Messages.attributes.icid description: The message injection connection ID. type: Number - contextPath: CiscoEmailSecurity.Messages.attributes.isCompleteData description: Whether all data is in the message. type: Boolean - contextPath: CiscoEmailSecurity.Messages.attributes.mailPolicy description: The message mail policy. type: String - contextPath: CiscoEmailSecurity.Messages.attributes.messageStatus description: The status of the message. type: String - contextPath: CiscoEmailSecurity.Messages.attributes.mid description: The message ID. type: Number - contextPath: CiscoEmailSecurity.Messages.attributes.recipient description: The recipient of the message. type: String - contextPath: CiscoEmailSecurity.Messages.attributes.replyTo description: Who the message is in reply to. type: String - contextPath: CiscoEmailSecurity.Messages.attributes.sbrs description: The message sender base score. type: String - contextPath: CiscoEmailSecurity.Messages.attributes.sender description: The message sender. type: String - contextPath: CiscoEmailSecurity.Messages.attributes.senderDomain description: The message sender domain. type: String - contextPath: CiscoEmailSecurity.Messages.attributes.senderGroup description: The message sender group. type: String - contextPath: CiscoEmailSecurity.Messages.attributes.senderIp description: The message sender IP address. type: String - contextPath: CiscoEmailSecurity.Messages.attributes.serialNumber description: The message serial number. type: String - contextPath: CiscoEmailSecurity.Messages.attributes.subject description: The message subject. type: String - contextPath: CiscoEmailSecurity.Messages.attributes.timestamp description: The message datetime. type: String - contextPath: CiscoEmailSecurity.Messages.attributes.verdictChart description: The message verdict chart. type: String - arguments: - description: 'Start datetime for the search, in the following format: YYYY-MM-DD hh:mm:ss. The seconds must be 00, due to an API limitation.' name: start_date required: true - description: 'End datetime for the search, in the following format: YYYY-MM-DD hh:mm:ss. The seconds must be 00, due to an API limitation.' name: end_date required: true - description: Cisco message ID to filter with. name: cisco_id required: true - description: Message ID to filter with. name: message_id required: true - description: Appliance serial number to filter with. name: appliance_serial_number required: true description: Retrieves details of a message. name: cisco-email-security-message-details-get outputs: - contextPath: CiscoEmailSecurity.Message.attachments description: The attachments of the message. type: String - contextPath: CiscoEmailSecurity.Message.direction description: The message direction. type: String - contextPath: CiscoEmailSecurity.Message.hostName description: The message host name. type: String - contextPath: CiscoEmailSecurity.Message.isCompleteData description: Is there in the message all the data. type: Number - contextPath: CiscoEmailSecurity.Message.mailPolicy description: The message mail policy. type: String - contextPath: CiscoEmailSecurity.Message.messageSize description: The size of the message. type: String - contextPath: CiscoEmailSecurity.Message.messageStatus description: The status of the message. type: String - contextPath: CiscoEmailSecurity.Message.mid description: Message ID. type: Number - contextPath: CiscoEmailSecurity.Message.midHeader description: The header message ID of the message. type: String - contextPath: CiscoEmailSecurity.Message.recipient description: The recipient of the message. type: String - contextPath: CiscoEmailSecurity.Message.sender description: The sender of the message. type: String - contextPath: CiscoEmailSecurity.Message.senderGroup description: The sender group of the message. type: String - contextPath: CiscoEmailSecurity.Message.sendingHostSummary.ipAddress description: The IP address of the host message. type: String - contextPath: CiscoEmailSecurity.Message.sendingHostSummary.reverseDnsHostname description: The dns host name of the message. type: String - contextPath: CiscoEmailSecurity.Message.sendingHostSummary.sbrsScore description: The sender base score host of the message. type: String - contextPath: CiscoEmailSecurity.Message.showAMP description: Is the AMP shown. type: Boolean - contextPath: CiscoEmailSecurity.Message.showDLP description: Wheter the DLP is shown. type: Boolean - contextPath: CiscoEmailSecurity.Message.showSummaryTimeBox description: Whether the summary time box is shown. type: Boolean - contextPath: CiscoEmailSecurity.Message.showURL description: Whether the URL is shown. type: Boolean - contextPath: CiscoEmailSecurity.Message.smtpAuthId description: The SMTP auth ID of the message. type: String - contextPath: CiscoEmailSecurity.Message.subject description: The message date subject. type: String - contextPath: CiscoEmailSecurity.Message.summary.description description: The message summary description. type: String - contextPath: CiscoEmailSecurity.Message.summary.lastEvent description: The message summary last event. type: Number - contextPath: CiscoEmailSecurity.Message.summary.timestamp description: The message summary timestamp. type: String - contextPath: CiscoEmailSecurity.Message.timestamp description: The message timestamp. type: String - arguments: - description: 'Start datetime for the search, in the following format: YYYY-MM-DD hh:mm:ss. The seconds must be 00, due to an API limitation.' name: start_date required: true - description: 'End datetime for the search, in the following format: YYYY-MM-DD hh:mm:ss. The seconds must be 00, due to an API limitation.' name: end_date required: true - description: |- Specify the number of records to retrieve. If you use a limit you should also use a offset. name: limit - description: |- Specify an offset value to retrieve a subset of records starting with the offset value. If you use an offset you should also set a retrieval limit. name: offset - description: From address to filter by. name: order_by_from_address - description: To address to filter by. name: order_by_to_address - description: Subject to filter by name: order_by_subject - auto: PREDEFINED description: 'From address order to filter by. Possible values are: "asc" and "desc".' name: order_dir_from_address predefined: - asc - desc - auto: PREDEFINED description: 'To address order to filter by. Possible values are: "asc" and "desc".' name: order_dir_to_address predefined: - asc - desc - auto: PREDEFINED description: 'Subject order to filter by. Possible values are: "asc" and "desc".' name: order_dir_subject predefined: - asc - desc - description: Recipient value to filter by. name: recipient_value - auto: PREDEFINED description: 'Recipient operator to filter by. Possible values are: "is", "begins_with", and "contains".' name: recipient_operator predefined: - is - begins_with - contains - description: Filter value to filter by. name: filter_value - auto: PREDEFINED description: 'Filter operator to filter by. Possible values are: "is", "begins_with", and "contains".' name: filter_operator predefined: - is - begins_with - contains description: Executes a search for spam quarantine. name: cisco-email-security-spam-quarantine-search - arguments: - description: Message ID to filter by. name: message_id required: true description: Retrieves details for a quarantined message. name: cisco-email-security-spam-quarantine-message-details-get - arguments: - description: 'Start datetime for the search, in the following format: YYYY-MM-DD hh:mm:ss. The seconds must be 00, due to an API limitation.' name: start_date required: true - description: 'End datetime for the search, in the following format: YYYY-MM-DD hh:mm:ss. The seconds must be 00, due to an API limitation.' name: end_date required: true - description: Cisco message ID to filter by. name: cisco_id required: true - description: Message ID to filter by. name: message_id required: true - description: Appliance serial number to filter by. name: appliance_serial_number required: true description: Retrieves details on a DLP. name: cisco-email-security-dlp-details-get outputs: - contextPath: CiscoEmailSecurity.DLP.attachments description: The attachments of the DLP. type: String - contextPath: CiscoEmailSecurity.DLP.direction description: The DLP direction. type: String - contextPath: CiscoEmailSecurity.DLP.dlpDetails.dlpMatchedContent.messagePart description: The message part of the DLP details. type: String - contextPath: CiscoEmailSecurity.DLP.dlpDetails.dlpMatchedContent.messagePartMatch.classifier description: The classifier of the DLP details. type: String - contextPath: CiscoEmailSecurity.DLP.dlpDetails.dlpMatchedContent.messagePartMatch.classifierMatch description: The classifier match of the DLP details. type: String - contextPath: CiscoEmailSecurity.DLP.dlpDetails.dlpPolicy description: The DLP policy. type: String - contextPath: CiscoEmailSecurity.DLP.dlpDetails.mid description: The message ID of the DLP details. type: String - contextPath: CiscoEmailSecurity.DLP.dlpDetails.riskFactor description: The risk factor of the DLP. type: Number - contextPath: CiscoEmailSecurity.DLP.dlpDetails.violationSeverity description: The violation severity of the DLP. type: String - contextPath: CiscoEmailSecurity.DLP.hostName description: The host name of the DLP. type: String - contextPath: CiscoEmailSecurity.DLP.messageSize description: The message size of the DLP. type: String - contextPath: CiscoEmailSecurity.DLP.mid description: The message ID of the DLP. type: Number - contextPath: CiscoEmailSecurity.DLP.midHeader description: The header message ID of the DLP. type: String - contextPath: CiscoEmailSecurity.DLP.recipient description: The recipient of the DLP. type: String - contextPath: CiscoEmailSecurity.DLP.sender description: The sender of the DLP. type: String - contextPath: CiscoEmailSecurity.DLP.senderGroup description: The sender group of the DLP. type: String - contextPath: CiscoEmailSecurity.DLP.sendingHostSummary.ipAddress description: The IP address of the host DLP. type: String - contextPath: CiscoEmailSecurity.DLP.sendingHostSummary.reverseDnsHostname description: The DNS host name of the DLP. type: String - contextPath: CiscoEmailSecurity.DLP.sendingHostSummary.sbrsScore description: The sender base score host of the DLP. type: String - contextPath: CiscoEmailSecurity.DLP.showDLPDetails description: Whether the DLP details are shown. type: Boolean - contextPath: CiscoEmailSecurity.DLP.smtpAuthId description: The SMTP auth ID of the DLP. type: String - contextPath: CiscoEmailSecurity.DLP.subject description: The subject of the DLP. type: String - contextPath: CiscoEmailSecurity.DLP.timestamp description: The datetime of the DLP. type: String - arguments: - description: 'Start datetime for the search, in the following format: YYYY-MM-DD hh:mm:ss. The seconds must be 00, due to an API limitation.' name: start_date required: true - description: 'End datetime for the search, in the following format: YYYY-MM-DD hh:mm:ss. The seconds must be 00, due to an API limitation.' name: end_date required: true - description: Cisco message ID to filter by. name: cisco_id required: true - description: Message ID to filter by. name: message_id required: true - description: Appliance serial number to filter by. name: appliance_serial_number required: true description: Retrieves details of an AMP. name: cisco-email-security-amp-details-get outputs: - contextPath: CiscoEmailSecurity.AMP.ampDetails.description description: The description of the AMP. type: String - contextPath: CiscoEmailSecurity.AMP.ampDetails.lastEvent description: Whether this is the last event of the AMP. type: Boolean - contextPath: CiscoEmailSecurity.AMP.ampDetails.timestamp description: The datetime of the AMP. type: String - contextPath: CiscoEmailSecurity.AMP.attachments description: The attachments of the AMP. type: String - contextPath: CiscoEmailSecurity.AMP.direction description: The direction of the AMP. type: String - contextPath: CiscoEmailSecurity.AMP.hostName description: The hostname of the AMP. type: String - contextPath: CiscoEmailSecurity.AMP.messageSize description: The message size of the AMP. type: String - contextPath: CiscoEmailSecurity.AMP.mid description: The message ID of the AMP. type: Number - contextPath: CiscoEmailSecurity.AMP.midHeader description: The header message ID of the AMP. type: String - contextPath: CiscoEmailSecurity.AMP.recipient description: The recipient of the AMP. type: String - contextPath: CiscoEmailSecurity.AMP.sender description: The sender of the AMP. type: String - contextPath: CiscoEmailSecurity.AMP.senderGroup description: The sender group of the AMP. type: String - contextPath: CiscoEmailSecurity.AMP.sendingHostSummary.ipAddress description: The IP address of the host AMP. type: String - contextPath: CiscoEmailSecurity.AMP.sendingHostSummary.reverseDnsHostname description: The DNS hostname of the AMP. type: String - contextPath: CiscoEmailSecurity.AMP.sendingHostSummary.sbrsScore description: The sender base score host of the AMP. type: String - contextPath: CiscoEmailSecurity.AMP.showAMPDetails description: Whether AMP details are shown. type: Boolean - contextPath: CiscoEmailSecurity.AMP.smtpAuthId description: The SMTP auth ID of the AMP. type: String - contextPath: CiscoEmailSecurity.AMP.subject description: The subject of the AMP. type: String - contextPath: CiscoEmailSecurity.AMP.timestamp description: The datetime of the AMP. type: String - arguments: - description: 'Start datetime for the search, in the following format: YYYY-MM-DD hh:mm:ss. The seconds must be 00, due to an API limitation.' name: start_date required: true - description: 'End datetime for the search, in the following format: YYYY-MM-DD hh:mm:ss. The seconds must be 00, due to an API limitation.' name: end_date required: true - description: Cisco message ID to filter by. name: cisco_id required: true - description: Message ID to filter by. name: message_id required: true - description: Appliance serial number to filter by. name: appliance_serial_number required: true description: Retrieves details of a URL. name: cisco-email-security-url-details-get outputs: - contextPath: CiscoEmailSecurity.URL.attachments description: The attachments of the URL. type: String - contextPath: CiscoEmailSecurity.URL.direction description: The direction of the URL. type: String - contextPath: CiscoEmailSecurity.URL.hostName description: The hostName of the URL. type: String - contextPath: CiscoEmailSecurity.URL.mid description: The message ID of the URL. type: Number - contextPath: CiscoEmailSecurity.URL.midHeader description: The header message ID of the URL. type: String - contextPath: CiscoEmailSecurity.URL.recipient description: The recipient of the URL. type: String - contextPath: CiscoEmailSecurity.URL.sdrAge description: The software defined radio age of the URL. type: String - contextPath: CiscoEmailSecurity.URL.sdrCategory description: The software defined radio category of the URL. type: String - contextPath: CiscoEmailSecurity.URL.sdrReputation description: The software defined radio reputation of the URL. type: String - contextPath: CiscoEmailSecurity.URL.sender description: The URL of the sender. type: String - contextPath: CiscoEmailSecurity.URL.senderGroup description: The sender group of the URL. type: String - contextPath: CiscoEmailSecurity.URL.sendingHostSummary.ipAddress description: The IP address of the host URL. type: String - contextPath: CiscoEmailSecurity.URL.sendingHostSummary.reverseDnsHostname description: The DNS host name of the URL. type: String - contextPath: CiscoEmailSecurity.URL.sendingHostSummary.sbrsScore description: The sender base score host of the URL. type: String - contextPath: CiscoEmailSecurity.URL.showURLDetails description: Whether the URL details are shown. type: Boolean - contextPath: CiscoEmailSecurity.URL.smtpAuthId description: The SMTP auth ID of the URL. type: String - contextPath: CiscoEmailSecurity.URL.subject description: The URL subject. type: String - contextPath: CiscoEmailSecurity.URL.urlDetails.description description: The description of the URL. type: String - contextPath: CiscoEmailSecurity.URL.urlDetails.lastEvent description: Whether this is the last event of the URL. type: Boolean - contextPath: CiscoEmailSecurity.URL.urlDetails.timestamp description: The datetime of the URL details. type: String - arguments: - description: A list of ID's to delete, comma separated. isArray: true name: messages_ids required: true description: Deletes quarantined messages. name: cisco-email-security-spam-quarantine-messages-delete - arguments: - description: A comma-separated list of IDs to release. isArray: true name: messages_ids required: true description: Releases quarantined messages. name: cisco-email-security-spam-quarantine-messages-release - arguments: - auto: PREDEFINED description: 'List type to filter by. Possible values are: "safelist" and "blocklist".' name: list_type predefined: - safelist - blocklist required: true - description: |- Specify an offset value to retrieve a subset of records starting with the offset value. If you use an offset you should also set a retrieval limit. name: limit - description: |- Specify an offset value to retrieve a subset of records starting with the offset value. If you use a offset you should also use a limit. name: offset - auto: PREDEFINED description: View by sender or recipient. name: view_by predefined: - sender - recipient required: true - auto: PREDEFINED description: 'How to order the results. Possible values are: "sender" and "recipient".' name: order_by predefined: - sender - recipient required: true description: Retrieves a list of entries. name: cisco-email-security-list-entries-get outputs: - contextPath: CiscoEmailSecurity.ListEntries.Safelist.senderList description: The safelist sender list. type: String - contextPath: CiscoEmailSecurity.ListEntries.Safelist.recipientAddresses description: The safelist recipient addresses. type: String - contextPath: CiscoEmailSecurity.ListEntries.Safelist.recipientList description: The safelist recipient list. type: String - contextPath: CiscoEmailSecurity.ListEntries.Safelist.senderAddresses description: The safelist sender addresses. type: Number - contextPath: CiscoEmailSecurity.ListEntries.Blocklist.senderList description: The block list sender list. type: String - contextPath: CiscoEmailSecurity.ListEntries.Blocklist.recipientAddresses description: The block list recipient addresses. type: String - contextPath: CiscoEmailSecurity.ListEntries.Blocklist.recipientList description: The block list recipient list. type: String - contextPath: CiscoEmailSecurity.ListEntries.Blocklist.senderAddresses description: The block list sender addresses. type: Number - arguments: - auto: PREDEFINED description: 'List type. Possible values are: "safelist" and "blocklist".' name: list_type predefined: - safelist - blocklist required: true - auto: PREDEFINED description: 'Select the action to perform on the list. Possible values are: "add", "edit", and "append".' name: action predefined: - add - edit - append required: true - description: A comma-separated list of recipient addresses on which to perform the action. separated) isArray: true name: recipient_addresses - description: A comma-separated list of recipient lists on which to perform the action. isArray: true name: recipient_list - description: A comma-separated list of sender addresses on which to perform the action. isArray: true name: sender_addresses - description: A comma-separated list of sender lists on which to perform the action. isArray: true name: sender_list - auto: PREDEFINED description: View by "sender" or "recipient". name: view_by predefined: - sender - recipient required: true description: Performs actions on list entries. Supports add, edit, and append. name: cisco-email-security-list-entry-add - arguments: - auto: PREDEFINED description: List type name: list_type predefined: - safelist - blocklist required: true - description: A comma-separated list of recipient lists to delete. name: recipient_list - description: A comma-seaprated list of sender lists to delete. name: sender_list - auto: PREDEFINED description: View by "sender" or "recipient". name: view_by predefined: - sender - recipient required: true description: Deletes a list entry. name: cisco-email-security-list-entry-delete dockerimage: demisto/python3:3.10.8.37753 runonce: false script: '-' subtype: python3 type: python tests: - No tests fromversion: 5.0.0 beta: true deprecated: true