CiscoEmailSecurity Deprecated
Deprecated. Use Cisco Security Management Appliance instead.
Network Security · Cisco Email Security (Beta) (Deprecated)
Details
| ID | CiscoEmailSecurity |
|---|---|
| Provider | Cisco Systems |
| Category | Network Security |
| From Version | 5.0.0 |
| Docker Image | demisto/python3:3.10.8.37753 |
| Supported Modules | Agentix |
README
Cisco Email Security is an email security gateway . It detects and blocks a wide variety of email-borne threats, such as malware, spam and phishing.
This integration was integrated and tested with version 13 of CiscoEmailSecurity
Configure CiscoEmailSecurity in Cortex
| Parameter | Description | Required |
|---|---|---|
| base_url | Server URL (e.g. https://192.168.0.1) | True |
| credentials | API Username | True |
| insecure | Trust any certificate (not secure) | False |
| proxy | Use system proxy settings | False |
| timeout | request timeout | False |
Commands
You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.
cisco-email-security-report-get
Retrieves details of an email security report by counter type.
Base Command
cisco-email-security-report-get
Input
| Argument Name | Description | Required |
|---|---|---|
| start_date | Start datetime for the search, in the following format: YYYY-MM-DD hh:mm:ss. The seconds must be 00, due to an API limitation. | Required |
| end_date | End datetime for the search, in the following format: YYYY-MM-DD hh:mm:ss. The seconds must be 00, due to an API limitation. | Required |
| counter | Fetch data from a specific counter. Possible values are “reporting_system”, “mail_incoming_traffic_summary”, “mail_vof_threat_summary”, “mail_vof_specific_threat_summary”, and “mail_amp_threat_summary”. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| CiscoEmailSecurity.Report.MailAmpThreatSummary.incoming_malicious | Number | The number of incoming malicious messages. |
| CiscoEmailSecurity.Report.MailAmpThreatSummary.outgoing_malicious | Number | The number of outgoing malicious messages. |
| CiscoEmailSecurity.Report.MailVofSpecificThreatSummary.threat_detected_virus_or_malware | Number | The number of the messages identified as a virus or malware. |
| CiscoEmailSecurity.Report.MailVofThreatSummary.threat_detected | Number | The total number of messages identified as a threat. |
| CiscoEmailSecurity.Report.ReportingSystem.heartbeat | Number | The reporting system heartbeat. |
| CiscoEmailSecurity.Report.ReportingSystem.end_time | String | The reporting end time. |
| CiscoEmailSecurity.Report.ReportingSystem.begin_time | String | The reporting start time. |
| CiscoEmailSecurity.Report.ReportingSystem.centralized_reporting_expired | Number | The number of messages that centralized reporting expired. |
| CiscoEmailSecurity.Report.ReportingSystem.centralized_reporting_enabled | Number | The number of messages that centralized reporting enabled. |
| CiscoEmailSecurity.Report.MailIncomingTrafficSummary.blocked_dmarc | Number | The number of blocked dmarc messages. |
| CiscoEmailSecurity.Report.MailIncomingTrafficSummary.blocked_invalid_recipient | Number | The number of blocked invalid recipient messages. |
| CiscoEmailSecurity.Report.MailIncomingTrafficSummary.blocked_reputation | Number | The number of blocked reputation messages. |
| CiscoEmailSecurity.Report.MailIncomingTrafficSummary.bulk_mail | Number | The number of bulk mail messages. |
| CiscoEmailSecurity.Report.MailIncomingTrafficSummary.detected_amp | Number | The number of detected amp messages. |
| CiscoEmailSecurity.Report.MailIncomingTrafficSummary.detected_spam | Number | The number of detected spam messages. |
| CiscoEmailSecurity.Report.MailIncomingTrafficSummary.detected_virus | Number | The number of detected virus messages. |
| CiscoEmailSecurity.Report.MailIncomingTrafficSummary.malicious_url | Number | The number of malicious URL messages. |
| CiscoEmailSecurity.Report.MailIncomingTrafficSummary.marketing_mail | Number | The number of blocked dmarc messages. |
| CiscoEmailSecurity.Report.MailIncomingTrafficSummary.social_mail | Number | The number of marketing mail messages. |
| CiscoEmailSecurity.Report.MailIncomingTrafficSummary.threat_content_filter | Number | The number of threat content filter messages. |
| CiscoEmailSecurity.Report.MailIncomingTrafficSummary.total_clean_recipients | Number | The total number of clean recipients. |
| CiscoEmailSecurity.Report.MailIncomingTrafficSummary.total_graymail_recipients | Number | The total number of graymail recipients. |
| CiscoEmailSecurity.Report.MailIncomingTrafficSummary.total_recipients | Number | The tota number of recipients. |
| CiscoEmailSecurity.Report.MailIncomingTrafficSummary.total_threat_recipients | Number | The total number of threat recipients. |
| CiscoEmailSecurity.Report.MailIncomingTrafficSummary.verif_decrypt_fail | Number | The number of verif decrypt fail messages. |
| CiscoEmailSecurity.Report.MailIncomingTrafficSummary.verif_decrypt_success | Number | The number of verif decrypt success messages. |
| CiscoEmailSecurity.Report.MailIncomingTrafficSummary.detected_spam_suspect | Number | The number of suspected spam messages. |
| CiscoEmailSecurity.Report.MailIncomingTrafficSummary.detected_spam_certain | Number | The number of certain spam certain messages. |
| CiscoEmailSecurity.Report.MailIncomingTrafficSummary.failed_spf | Number | The number of failed spf messages. |
| CiscoEmailSecurity.Report.MailIncomingTrafficSummary.failed_dkim | Number | The number of failed dkim messages. |
| CiscoEmailSecurity.Report.MailIncomingTrafficSummary.total_spoofed_emails | Number | The total number of spoofed email messages. |
| CiscoEmailSecurity.Report.MailIncomingTrafficSummary.total_mailbox_auto_remediated_recipients | Number | The total number of mailbox auto-remediated recipients. |
| CiscoEmailSecurity.Report.MailIncomingTrafficSummary.detected_virus_per_msg | Number | The number of detected virus per msg messages. |
| CiscoEmailSecurity.Report.MailIncomingTrafficSummary.ims_spam_increment_over_case | Number | The number of ims spam increment over case messages. |
cisco-email-security-messages-search
Executes a search for messages in Cisco Email Security.
Base Command
cisco-email-security-messages-search
Input
| Argument Name | Description | Required |
|---|---|---|
| start_date | Start datetime for the search, in the following format: YYYY-MM-DD hh:mm:ss. The seconds must be 00, due to an API limitation. | Required |
| end_date | End datetime for the search, in the following format: YYYY-MM-DD hh:mm:ss. The seconds must be 00, due to an API limitation. | Required |
| limit | The maximum number of records to retrieve. If you set a limit you should also use an offset. |
Optional |
| offset | Specify an offset value to retrieve a subset of records starting with the offset value. If you use an offset you should also set a retrieval limit. |
Optional |
| attachment_name_operator | Attachment name operator to filter by. If you want to use attachment, you need to pass the following arguments: attachment_name_operator and attachment_name_value. Possible values are: “is”, “begins_with”, and “contains”. |
Optional |
| attachment_name_value | Attachment name value to filter by. If you want to use attachment, you need to pass the following arguments: attachment_name_operator and attachment_name_value. |
Optional |
| file_hash | File SHA256 hash to filter by. | Optional |
| recipient_filter_operator | Recipient filter operator to filter by. If you want to use recipient, you need to pass the following arguments: recipient_filter_operator and recipient_filter_value. Possible values are: “is”, “begins_with”, and “contains”. |
Optional |
| recipient_filter_value | Recipient filter value to filter with. If you want to use recipient, you need to pass the following arguments: recipient_filter_operator and recipient_filter_value. |
Optional |
| sender_filter_operator | Sender filter operator to filter with. If you want to use sender, you need to pass the following arguments: sender_filter_operator and sender_filter_value. Possible values are: “is”, “begins_with”, and “contains”. |
Optional |
| sender_filter_value | Sender filter value to filter by. If you want to use sender, you need to pass the following arguments: sender_filter_operator and sender_filter_value. |
Optional |
| subject_filter_operator | Subject filter operator to filter by If you want to use subject, you need to pass the following arguments: subject_filter_operator and subject_filter_value. Possible values are: “is”, “begins_with”, and “contains”. |
Optional |
| subject_filter_value | Subject filter value to filter by. If you want to use subject, you need to pass the following arguments: subject_filter_operator and subject_filter_value. |
Optional |
| message_id | Message ID to filter with | Optional |
| cisco_message_id | Cisco message ID to filter by. | Optional |
| sender_ip | Sender IP address to filter by. | Optional |
| message_direction | Message direction to filter by. Possible values are “incoming” and “outgoing”. | Optional |
| spam_positive | Whether to filter by positive spam positive. Possible values are: “True” and “False”. | Optional |
| quarantined_as_spam | Whether to filter by in spam quarantine. Possible values: are “True” and “False”. | Optional |
| quarantine_status | Quarantine status to filter. Possible values are: “POLICY”, “AMP”, “AV”, “UNCLASSIFIED”, “DLP”, and “OUTBREAK”. | Optional |
| url_reputation | URL reputation to filter by. Possible values are: “Malicious” and “Suspicious”. | Optional |
| virus_positive | Virus positive to filter by. Possible values are: “True” and “False”. | Optional |
| domain_name_operator | Domain name operator to filter by. If you want to use domain filter, you need to pass the following arguments: domain_name_operator and domain_name_value. Possible values are: “is”, “begins_with”, and “contains”. |
Optional |
| domain_name_value | Domain name value to filter by. If you want to use domain filter, you need to pass the following arguments: domain_name_operator and domain_name_value. |
Optional |
| contained_malicious_urls | Whether to filter by contained malicious URLs. Possible values are: “True” and “False”. | Optional |
| contained_neutral_urls | Whether to filter by is contained natural URLs. Possible values are: “True” and “False”. | Optional |
| macro_file_types_detected | Macro file types detected to filter by. temlate of macro_file_types_detected - Microsoft%20Office%20Files,Adobe%20Portable%20Document%20Format |
Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| CiscoEmailSecurity.Messages.attributes.direction | String | The message direction. |
| CiscoEmailSecurity.Messages.attributes.hostName | String | The message hostName. |
| CiscoEmailSecurity.Messages.attributes.icid | Number | The message injection connection ID. |
| CiscoEmailSecurity.Messages.attributes.isCompleteData | Boolean | Whether all data is in the message. |
| CiscoEmailSecurity.Messages.attributes.mailPolicy | String | The message mail policy. |
| CiscoEmailSecurity.Messages.attributes.messageStatus | String | The status of the message. |
| CiscoEmailSecurity.Messages.attributes.mid | Number | The message ID. |
| CiscoEmailSecurity.Messages.attributes.recipient | String | The recipient of the message. |
| CiscoEmailSecurity.Messages.attributes.replyTo | String | Who the message is in reply to. |
| CiscoEmailSecurity.Messages.attributes.sbrs | String | The message sender base score. |
| CiscoEmailSecurity.Messages.attributes.sender | String | The message sender. |
| CiscoEmailSecurity.Messages.attributes.senderDomain | String | The message sender domain. |
| CiscoEmailSecurity.Messages.attributes.senderGroup | String | The message sender group. |
| CiscoEmailSecurity.Messages.attributes.senderIp | String | The message sender IP address. |
| CiscoEmailSecurity.Messages.attributes.serialNumber | String | The message serial number. |
| CiscoEmailSecurity.Messages.attributes.subject | String | The message subject. |
| CiscoEmailSecurity.Messages.attributes.timestamp | String | The message datetime. |
| CiscoEmailSecurity.Messages.attributes.verdictChart | String | The message verdict chart. |
cisco-email-security-message-details-get
Retrieves details of a message.
Base Command
cisco-email-security-message-details-get
Input
| Argument Name | Description | Required |
|---|---|---|
| start_date | Start datetime for the search, in the following format: YYYY-MM-DD hh:mm:ss. The seconds must be 00, due to an API limitation. | Required |
| end_date | End datetime for the search, in the following format: YYYY-MM-DD hh:mm:ss. The seconds must be 00, due to an API limitation. | Required |
| cisco_id | Cisco message ID to filter with. | Required |
| message_id | Message ID to filter with. | Required |
| appliance_serial_number | Appliance serial number to filter with. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| CiscoEmailSecurity.Message.attachments | String | The attachments of the message. |
| CiscoEmailSecurity.Message.direction | String | The message direction. |
| CiscoEmailSecurity.Message.hostName | String | The message host name. |
| CiscoEmailSecurity.Message.isCompleteData | Number | Is there in the message all the data. |
| CiscoEmailSecurity.Message.mailPolicy | String | The message mail policy. |
| CiscoEmailSecurity.Message.messageSize | String | The size of the message. |
| CiscoEmailSecurity.Message.messageStatus | String | The status of the message. |
| CiscoEmailSecurity.Message.mid | Number | Message ID. |
| CiscoEmailSecurity.Message.midHeader | String | The header message ID of the message. |
| CiscoEmailSecurity.Message.recipient | String | The recipient of the message. |
| CiscoEmailSecurity.Message.sender | String | The sender of the message. |
| CiscoEmailSecurity.Message.senderGroup | String | The sender group of the message. |
| CiscoEmailSecurity.Message.sendingHostSummary.ipAddress | String | The IP address of the host message. |
| CiscoEmailSecurity.Message.sendingHostSummary.reverseDnsHostname | String | The dns host name of the message. |
| CiscoEmailSecurity.Message.sendingHostSummary.sbrsScore | String | The sender base score host of the message. |
| CiscoEmailSecurity.Message.showAMP | Boolean | Is the AMP shown. |
| CiscoEmailSecurity.Message.showDLP | Boolean | Wheter the DLP is shown. |
| CiscoEmailSecurity.Message.showSummaryTimeBox | Boolean | Whether the summary time box is shown. |
| CiscoEmailSecurity.Message.showURL | Boolean | Whether the URL is shown. |
| CiscoEmailSecurity.Message.smtpAuthId | String | The SMTP auth ID of the message. |
| CiscoEmailSecurity.Message.subject | String | The message date subject. |
| CiscoEmailSecurity.Message.summary.description | String | The message summary description. |
| CiscoEmailSecurity.Message.summary.lastEvent | Number | The message summary last event. |
| CiscoEmailSecurity.Message.summary.timestamp | String | The message summary timestamp. |
| CiscoEmailSecurity.Message.timestamp | String | The message timestamp. |
cisco-email-security-spam-quarantine-search
Executes a search for spam quarantine.
Base Command
cisco-email-security-spam-quarantine-search
Input
| Argument Name | Description | Required |
|---|---|---|
| start_date | Start datetime for the search, in the following format: YYYY-MM-DD hh:mm:ss. The seconds must be 00, due to an API limitation. | Required |
| end_date | End datetime for the search, in the following format: YYYY-MM-DD hh:mm:ss. The seconds must be 00, due to an API limitation. | Required |
| limit | Specify the number of records to retrieve. If you use a limit you should also use a offset. |
Optional |
| offset | Specify an offset value to retrieve a subset of records starting with the offset value. If you use an offset you should also set a retrieval limit. |
Optional |
| order_by_from_address | From address to filter by. | Optional |
| order_by_to_address | To address to filter by. | Optional |
| order_by_subject | Subject to filter by | Optional |
| order_dir_from_address | From address order to filter by. Possible values are: “asc” and “desc”. | Optional |
| order_dir_to_address | To address order to filter by. Possible values are: “asc” and “desc”. | Optional |
| order_dir_subject | Subject order to filter by. Possible values are: “asc” and “desc”. | Optional |
| recipient_value | Recipient value to filter by. | Optional |
| recipient_operator | Recipient operator to filter by. Possible values are: “is”, “begins_with”, and “contains”. | Optional |
| filter_value | Filter value to filter by. | Optional |
| filter_operator | Filter operator to filter by. Possible values are: “is”, “begins_with”, and “contains”. | Optional |
Context Output
There is no context output for this command.
cisco-email-security-spam-quarantine-message-details-get
Retrieves details for a quarantined message.
Base Command
cisco-email-security-spam-quarantine-message-details-get
Input
| Argument Name | Description | Required |
|---|---|---|
| message_id | Message ID to filter by. | Required |
Context Output
There is no context output for this command.
cisco-email-security-dlp-details-get
Retrieves details on a DLP.
Base Command
cisco-email-security-dlp-details-get
Input
| Argument Name | Description | Required |
|---|---|---|
| start_date | Start datetime for the search, in the following format: YYYY-MM-DD hh:mm:ss. The seconds must be 00, due to an API limitation. | Required |
| end_date | End datetime for the search, in the following format: YYYY-MM-DD hh:mm:ss. The seconds must be 00, due to an API limitation. | Required |
| cisco_id | Cisco message ID to filter by. | Required |
| message_id | Message ID to filter by. | Required |
| appliance_serial_number | Appliance serial number to filter by. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| CiscoEmailSecurity.DLP.attachments | String | The attachments of the DLP. |
| CiscoEmailSecurity.DLP.direction | String | The DLP direction. |
| CiscoEmailSecurity.DLP.dlpDetails.dlpMatchedContent.messagePart | String | The message part of the DLP details. |
| CiscoEmailSecurity.DLP.dlpDetails.dlpMatchedContent.messagePartMatch.classifier | String | The classifier of the DLP details. |
| CiscoEmailSecurity.DLP.dlpDetails.dlpMatchedContent.messagePartMatch.classifierMatch | String | The classifier match of the DLP details. |
| CiscoEmailSecurity.DLP.dlpDetails.dlpPolicy | String | The DLP policy. |
| CiscoEmailSecurity.DLP.dlpDetails.mid | String | The message ID of the DLP details. |
| CiscoEmailSecurity.DLP.dlpDetails.riskFactor | Number | The risk factor of the DLP. |
| CiscoEmailSecurity.DLP.dlpDetails.violationSeverity | String | The violation severity of the DLP. |
| CiscoEmailSecurity.DLP.hostName | String | The host name of the DLP. |
| CiscoEmailSecurity.DLP.messageSize | String | The message size of the DLP. |
| CiscoEmailSecurity.DLP.mid | Number | The message ID of the DLP. |
| CiscoEmailSecurity.DLP.midHeader | String | The header message ID of the DLP. |
| CiscoEmailSecurity.DLP.recipient | String | The recipient of the DLP. |
| CiscoEmailSecurity.DLP.sender | String | The sender of the DLP. |
| CiscoEmailSecurity.DLP.senderGroup | String | The sender group of the DLP. |
| CiscoEmailSecurity.DLP.sendingHostSummary.ipAddress | String | The IP address of the host DLP. |
| CiscoEmailSecurity.DLP.sendingHostSummary.reverseDnsHostname | String | The DNS host name of the DLP. |
| CiscoEmailSecurity.DLP.sendingHostSummary.sbrsScore | String | The sender base score host of the DLP. |
| CiscoEmailSecurity.DLP.showDLPDetails | Boolean | Whether the DLP details are shown. |
| CiscoEmailSecurity.DLP.smtpAuthId | String | The SMTP auth ID of the DLP. |
| CiscoEmailSecurity.DLP.subject | String | The subject of the DLP. |
| CiscoEmailSecurity.DLP.timestamp | String | The datetime of the DLP. |
cisco-email-security-amp-details-get
Retrieves details of an AMP.
Base Command
cisco-email-security-amp-details-get
Input
| Argument Name | Description | Required |
|---|---|---|
| start_date | Start datetime for the search, in the following format: YYYY-MM-DD hh:mm:ss. The seconds must be 00, due to an API limitation. | Required |
| end_date | End datetime for the search, in the following format: YYYY-MM-DD hh:mm:ss. The seconds must be 00, due to an API limitation. | Required |
| cisco_id | Cisco message ID to filter by. | Required |
| message_id | Message ID to filter by. | Required |
| appliance_serial_number | Appliance serial number to filter by. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| CiscoEmailSecurity.AMP.ampDetails.description | String | The description of the AMP. |
| CiscoEmailSecurity.AMP.ampDetails.lastEvent | Boolean | Whether this is the last event of the AMP. |
| CiscoEmailSecurity.AMP.ampDetails.timestamp | String | The datetime of the AMP. |
| CiscoEmailSecurity.AMP.attachments | String | The attachments of the AMP. |
| CiscoEmailSecurity.AMP.direction | String | The direction of the AMP. |
| CiscoEmailSecurity.AMP.hostName | String | The hostname of the AMP. |
| CiscoEmailSecurity.AMP.messageSize | String | The message size of the AMP. |
| CiscoEmailSecurity.AMP.mid | Number | The message ID of the AMP. |
| CiscoEmailSecurity.AMP.midHeader | String | The header message ID of the AMP. |
| CiscoEmailSecurity.AMP.recipient | String | The recipient of the AMP. |
| CiscoEmailSecurity.AMP.sender | String | The sender of the AMP. |
| CiscoEmailSecurity.AMP.senderGroup | String | The sender group of the AMP. |
| CiscoEmailSecurity.AMP.sendingHostSummary.ipAddress | String | The IP address of the host AMP. |
| CiscoEmailSecurity.AMP.sendingHostSummary.reverseDnsHostname | String | The DNS hostname of the AMP. |
| CiscoEmailSecurity.AMP.sendingHostSummary.sbrsScore | String | The sender base score host of the AMP. |
| CiscoEmailSecurity.AMP.showAMPDetails | Boolean | Whether AMP details are shown. |
| CiscoEmailSecurity.AMP.smtpAuthId | String | The SMTP auth ID of the AMP. |
| CiscoEmailSecurity.AMP.subject | String | The subject of the AMP. |
| CiscoEmailSecurity.AMP.timestamp | String | The datetime of the AMP. |
cisco-email-security-url-details-get
Retrieves details of a URL.
Base Command
cisco-email-security-url-details-get
Input
| Argument Name | Description | Required |
|---|---|---|
| start_date | Start datetime for the search, in the following format: YYYY-MM-DD hh:mm:ss. The seconds must be 00, due to an API limitation. | Required |
| end_date | End datetime for the search, in the following format: YYYY-MM-DD hh:mm:ss. The seconds must be 00, due to an API limitation. | Required |
| cisco_id | Cisco message ID to filter by. | Required |
| message_id | Message ID to filter by. | Required |
| appliance_serial_number | Appliance serial number to filter by. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| CiscoEmailSecurity.URL.attachments | String | The attachments of the URL. |
| CiscoEmailSecurity.URL.direction | String | The direction of the URL. |
| CiscoEmailSecurity.URL.hostName | String | The hostName of the URL. |
| CiscoEmailSecurity.URL.mid | Number | The message ID of the URL. |
| CiscoEmailSecurity.URL.midHeader | String | The header message ID of the URL. |
| CiscoEmailSecurity.URL.recipient | String | The recipient of the URL. |
| CiscoEmailSecurity.URL.sdrAge | String | The software defined radio age of the URL. |
| CiscoEmailSecurity.URL.sdrCategory | String | The software defined radio category of the URL. |
| CiscoEmailSecurity.URL.sdrReputation | String | The software defined radio reputation of the URL. |
| CiscoEmailSecurity.URL.sender | String | The URL of the sender. |
| CiscoEmailSecurity.URL.senderGroup | String | The sender group of the URL. |
| CiscoEmailSecurity.URL.sendingHostSummary.ipAddress | String | The IP address of the host URL. |
| CiscoEmailSecurity.URL.sendingHostSummary.reverseDnsHostname | String | The DNS host name of the URL. |
| CiscoEmailSecurity.URL.sendingHostSummary.sbrsScore | String | The sender base score host of the URL. |
| CiscoEmailSecurity.URL.showURLDetails | Boolean | Whether the URL details are shown. |
| CiscoEmailSecurity.URL.smtpAuthId | String | The SMTP auth ID of the URL. |
| CiscoEmailSecurity.URL.subject | String | The URL subject. |
| CiscoEmailSecurity.URL.urlDetails.description | String | The description of the URL. |
| CiscoEmailSecurity.URL.urlDetails.lastEvent | Boolean | Whether this is the last event of the URL. |
| CiscoEmailSecurity.URL.urlDetails.timestamp | String | The datetime of the URL details. |
cisco-email-security-spam-quarantine-messages-delete
Deletes quarantined messages.
Base Command
cisco-email-security-spam-quarantine-messages-delete
Input
| Argument Name | Description | Required |
|---|---|---|
| messages_ids | A list of ID’s to delete, comma separated. | Required |
Context Output
There is no context output for this command.
cisco-email-security-spam-quarantine-messages-release
Releases quarantined messages.
Base Command
cisco-email-security-spam-quarantine-messages-release
Input
| Argument Name | Description | Required |
|---|---|---|
| messages_ids | A comma-separated list of IDs to release. | Required |
Context Output
There is no context output for this command.
cisco-email-security-list-entries-get
Retrieves a list of entries.
Base Command
cisco-email-security-list-entries-get
Input
| Argument Name | Description | Required |
|---|---|---|
| list_type | List type to filter by. Possible values are: “safelist” and “blocklist”. | Required |
| limit | Specify an offset value to retrieve a subset of records starting with the offset value. If you use an offset you should also set a retrieval limit. |
Optional |
| offset | Specify an offset value to retrieve a subset of records starting with the offset value. If you use a offset you should also use a limit. |
Optional |
| view_by | View by sender or recipient. | Required |
| order_by | How to order the results. Possible values are: “sender” and “recipient”. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| CiscoEmailSecurity.ListEntries.Safelist.senderList | String | The safelist sender list. |
| CiscoEmailSecurity.ListEntries.Safelist.recipientAddresses | String | The safelist recipient addresses. |
| CiscoEmailSecurity.ListEntries.Safelist.recipientList | String | The safelist recipient list. |
| CiscoEmailSecurity.ListEntries.Safelist.senderAddresses | Number | The safelist sender addresses. |
| CiscoEmailSecurity.ListEntries.Blocklist.senderList | String | The block list sender list. |
| CiscoEmailSecurity.ListEntries.Blocklist.recipientAddresses | String | The block list recipient addresses. |
| CiscoEmailSecurity.ListEntries.Blocklist.recipientList | String | The block list recipient list. |
| CiscoEmailSecurity.ListEntries.Blocklist.senderAddresses | Number | The bloc klist sender addresses. |
cisco-email-security-list-entry-add
Performs actions on list entries. Supports add, edit, and append.
Base Command
cisco-email-security-list-entry-add
Input
| Argument Name | Description | Required |
|---|---|---|
| list_type | List type. Possible values are: “safelist” and “blocklist”. | Required |
| action | Select the action to perform on the list. Possible values are: “add”, “edit”, and “append”. | Required |
| recipient_addresses | A comma-separated list of recipient addresses on which to perform the action. separated) | Optional |
| recipient_list | A comma-separated list of recipient lists on which to perform the action. | Optional |
| sender_addresses | A comma-separated list of sender addresses on which to perform the action. | Optional |
| sender_list | A comma-separated list of sender lists on which to perform the action. | Optional |
| view_by | View by “sender” or “recipient”. | Required |
Context Output
There is no context output for this command.
cisco-email-security-list-entry-delete
Deletes a list entry.
Base Command
cisco-email-security-list-entry-delete
Input
| Argument Name | Description | Required |
|---|---|---|
| list_type | List type | Required |
| recipient_list | A comma-separated list of recipient lists to delete. | Optional |
| sender_list | A comma-seaprated list of sender lists to delete. | Optional |
| view_by | View by “sender” or “recipient”. | Required |
Context Output
There is no context output for this command.
Configuration parameters
base_url— Server URL (e.g. https://192.168.0.1) (required)credentials— API Username (required)insecure— Trust any certificate (not secure)proxy— Use system proxy settingstimeout— Request Timeout
Commands (13)
-
cisco-email-security-amp-details-getRetrieves details of an AMP.
-
cisco-email-security-dlp-details-getRetrieves details on a DLP.
-
cisco-email-security-list-entries-getRetrieves a list of entries.
-
cisco-email-security-list-entry-addPerforms actions on list entries. Supports add, edit, and append.
-
cisco-email-security-list-entry-deleteDeletes a list entry.
-
cisco-email-security-message-details-getRetrieves details of a message.
-
cisco-email-security-messages-searchExecutes a search for messages in Cisco Email Security.
-
cisco-email-security-report-getRetrieves details of an email security report by counter type.
-
cisco-email-security-spam-quarantine-message-details-getRetrieves details for a quarantined message.
-
cisco-email-security-spam-quarantine-messages-deleteDeletes quarantined messages.
-
cisco-email-security-spam-quarantine-messages-releaseReleases quarantined messages.
-
cisco-email-security-spam-quarantine-searchExecutes a search for spam quarantine.
-
cisco-email-security-url-details-getRetrieves details of a URL.
import json import pytest from CiscoEmailSecurity import Client def get_fetch_data(): with open('./test_data/test_data.json', 'r') as f: return json.loads(f.read()) test_data = get_fetch_data() def test_date_to_cisco_date(): from CiscoEmailSecurity import date_to_cisco_date res = date_to_cisco_date('2019-11-20 09:36:09') assert res == '2019-11-20T09:36:09.000Z' @pytest.mark.parametrize( "limit, expected", [ ('', 20), ('100', 20), ('15', 15) ] ) def test_set_limit(limit, expected): from CiscoEmailSecurity import set_limit res = set_limit(limit) assert res == expected def test_set_var_to_output_prefix(): from CiscoEmailSecurity import set_var_to_output_prefix res = set_var_to_output_prefix('mail_incoming_traffic_summary') assert res == 'MailIncomingTrafficSummary' def test_build_url_params_for_list_report(): """ Given: Arguments To flirt with. When: The function builds a URL filter from these arguments. Then: We check that the URL filter matches what the command asks for. """ from CiscoEmailSecurity import build_url_params_for_list_report res = build_url_params_for_list_report(test_data['args_for_list_report'], 'reporting_system') assert res == test_data['url_params_for_list_reports'] def test_build_url_params_for_list_messages(): """ Given: Arguments To flirt with. When: The function builds a URL filter from these arguments. Then: We check that the URL filter matches what the command asks for. """ from CiscoEmailSecurity import build_url_params_for_list_messages res = build_url_params_for_list_messages(test_data['args_for_list_messages']) assert res == test_data['url_params_for_list_messages'] def test_build_url_params_for_get_details(): """ Given: Arguments To flirt with. When: The function builds a URL filter from these arguments. Then: We check that the URL filter matches what the command asks for. """ from CiscoEmailSecurity import build_url_params_for_get_details res = build_url_params_for_get_details(test_data['args_for_get_details']) assert res == test_data['url_params_for_get_details'] def test_build_url_params_for_spam_quarantine(): """ Given: Arguments To flirt with. When: The function builds a URL filter from these arguments. Then: We check that the URL filter matches what the command asks for. """ from CiscoEmailSecurity import build_url_params_for_spam_quarantine res = build_url_params_for_spam_quarantine(test_data['args_for_spam_quarantine']) assert res == test_data['url_params_for_spam_quarantine'] def test_list_search_messages_command(requests_mock): """ Given: Arguments for command - list_search_messages. When: The API gives us results according to the arguments we sent. Then: We check that what is in context (outputs, outputs_prefix, outputs_key_field) is what should be according to the arguments we sent to the API. """ from CiscoEmailSecurity import list_search_messages_command requests_mock.post("https://ciscoemailsecurity/sma/api/v2.0/login", json=test_data['data_for_login']) requests_mock.get("https://ciscoemailsecurity/sma/api/v2.0/message-tracking/messages?" "startDate=2017-02-14T09:51:46.000-0600.000Z&endDate=2017-02-14T09:51:46.000-0600.000Z" "&searchOption=messages&ciscoHost=All_Hosts&offset=0&limit=20", json=test_data['search_messages_response_data']) client = Client({"credentials": {"identifier": "a", "password": "b"}, "base_url": "https://ciscoemailsecurity/", "insecure": False, "proxy": False, "timeout": "2000"}) res = list_search_messages_command(client, {"start_date": "2017-02-14T09:51:46.000-0600", "end_date": "2017-02-14T09:51:46.000-0600"}) assert res.outputs == test_data['search_messages_context'] assert res.outputs_prefix == 'CiscoEmailSecurity.Message' assert res.outputs_key_field == 'attributes.mid' def test_messages_to_human_readable(): """ Given: Messages response data. When: The function arranges the data and returns it in the Markdown table. Then: We check that the table that the function returns corresponds to the data that the function received. """ from CiscoEmailSecurity import messages_to_human_readable res = messages_to_human_readable(test_data['search_messages_context']) assert res == test_data['messages_human_readable'] def test_list_get_message_details_command(requests_mock): """ Given: Arguments for command - list_get_message_details. When: The API gives us results according to the arguments we sent. Then: We check that what is in context (outputs, outputs_prefix, outputs_key_field) is what should be according to the arguments we sent to the API. """ from CiscoEmailSecurity import list_get_message_details_command requests_mock.post("https://ciscoemailsecurity/sma/api/v2.0/login", json=test_data['data_for_login']) requests_mock.get("https://ciscoemailsecurity/sma/api/v2.0/message-tracking/details?" "startDate=2017-02-14T09:51:46.000-0600.000Z&endDate=2017-02-14T09:51:46.000-0600.000Z&" "mid=None&icid=None", json=test_data['get_message_details_response_data']) client = Client({"credentials": {"identifier": "a", "password": "b"}, "base_url": "https://ciscoemailsecurity/", "insecure": False, "proxy": False, "timeout": "2000"}) res = list_get_message_details_command(client, {"start_date": "2017-02-14T09:51:46.000-0600", "end_date": "2017-02-14T09:51:46.000-0600"}) assert res.outputs == test_data['get_message_details_context'] assert res.outputs_prefix == 'CiscoEmailSecurity.Message' assert res.outputs_key_field == 'mid' def test_message_to_human_readable(): """ Given: Message response data. When: The function arranges the data and returns it in the Markdown table. Then: We check that the table that the function returns corresponds to the data that the function received. """ from CiscoEmailSecurity import details_get_to_human_readable res = details_get_to_human_readable(test_data['get_message_details_context']) assert res == test_data['message_human_readable'] def test_list_search_spam_quarantine_command(requests_mock): """ Given: Arguments for command - list_search_spam_quarantine. When: The API gives us results according to the arguments we sent. Then: We check that what is in context (outputs, outputs_prefix, outputs_key_field) is what should be according to the arguments we sent to the API. """ from CiscoEmailSecurity import list_search_spam_quarantine_command requests_mock.post("https://ciscoemailsecurity/sma/api/v2.0/login", json=test_data['data_for_login']) requests_mock.get("https://ciscoemailsecurity/sma/api/v2.0/quarantine/messages" "?startDate=2017-02-14T09:51:46.000-0600.000Z&endDate=2017-02-14T09:51:46.000-0600.000Z" "&quarantineType=spam&offset=0&limit=20", json=test_data['search_spam_quarantine_response_data']) client = Client({"credentials": {"identifier": "a", "password": "b"}, "base_url": "https://ciscoemailsecurity/", "insecure": False, "proxy": False, "timeout": "2000"}) res = list_search_spam_quarantine_command(client, {"start_date": "2017-02-14T09:51:46.000-0600", "end_date": "2017-02-14T09:51:46.000-0600"}) assert res.outputs == test_data['search_spam_quarantine_context'] assert res.outputs_prefix == 'CiscoEmailSecurity.SpamQuarantine' assert res.outputs_key_field == 'mid' def test_spam_quarantine_to_human_readable(): """ Given: Spam quarantine response data. When: The function arranges the data and returns it in the Markdown table. Then: We check that the table that the function returns corresponds to the data that the function received. """ from CiscoEmailSecurity import spam_quarantine_to_human_readable res = spam_quarantine_to_human_readable(test_data['search_spam_quarantine_context']) assert res == test_data['spam_quarantine_human_readable'] def test_list_get_quarantine_message_details_command(requests_mock): """ Given: Arguments for command - get_quarantine_message_details. When: The API gives us results according to the arguments we sent. Then: We check that what is in context (outputs, outputs_prefix, outputs_key_field) is what should be according to the arguments we sent to the API. """ from CiscoEmailSecurity import list_get_quarantine_message_details_command requests_mock.post("https://ciscoemailsecurity/sma/api/v2.0/login", json=test_data['data_for_login']) requests_mock.get("https://ciscoemailsecurity/sma/api/v2.0/quarantine/messages/details?mid=None" "&quarantineType=spam", json=test_data['quarantine_message_details_response_data']) client = Client({"credentials": {"identifier": "a", "password": "b"}, "base_url": "https://ciscoemailsecurity/", "insecure": False, "proxy": False, "timeout": "2000"}) res = list_get_quarantine_message_details_command(client, {"start_date": "2017-02-14T09:51:46.000-0600", "end_date": "2017-02-14T09:51:46.000-0600"}) assert res.outputs == test_data['quarantine_message_details_context'] assert res.outputs_prefix == 'CiscoEmailSecurity.QuarantineMessageDetail' assert res.outputs_key_field == 'mid' def test_quarantine_message_details_data_to_human_readable(): """ Given: Spam quarantine message details response data. When: The function arranges the data and returns it in the Markdown table. Then: We check that the table that the function returns corresponds to the data that the function received. """ from CiscoEmailSecurity import quarantine_message_details_data_to_human_readable res = quarantine_message_details_data_to_human_readable(test_data['quarantine_message_context_to_human_readable']) assert res == test_data['quarantine_message_details_human_readable'] def test_list_delete_quarantine_messages_command(requests_mock): """ Given: Arguments for command - delete_quarantine_messages. When: The API gives us results according to the arguments we sent. Then: We check that what is in context (readable_output, outputs_prefix) is what should be according to the arguments we sent to the API. """ from CiscoEmailSecurity import list_delete_quarantine_messages_command requests_mock.post("https://ciscoemailsecurity/sma/api/v2.0/login", json=test_data['data_for_login']) requests_mock.delete("https://ciscoemailsecurity/sma/api/v2.0/quarantine/messages", json=test_data['quarantine_delete_message_response_data']) client = Client({"credentials": {"identifier": "a", "password": "b"}, "base_url": "https://ciscoemailsecurity/", "insecure": False, "proxy": False, "timeout": "2000"}) res = list_delete_quarantine_messages_command(client, {"messages_ids": "1234"}) assert res.readable_output == test_data['quarantine_delete_message_response_data'] def test_list_release_quarantine_messages_command(requests_mock): """ Given: Arguments for command - release_quarantine_messages. When: The API gives us results according to the arguments we sent. Then: We check that what is in context (readable_output, outputs_prefix) is what should be according to the arguments we sent to the API. """ from CiscoEmailSecurity import list_release_quarantine_messages_command requests_mock.post("https://ciscoemailsecurity/sma/api/v2.0/login", json=test_data['data_for_login']) requests_mock.post("https://ciscoemailsecurity/sma/api/v2.0/quarantine/messages", json=test_data['quarantine_release_message_response_data']) client = Client({"credentials": {"identifier": "a", "password": "b"}, "base_url": "https://ciscoemailsecurity/", "insecure": False, "proxy": False, "timeout": "2000"}) res = list_release_quarantine_messages_command(client, {"messages_ids": "1234"}) assert res.readable_output == test_data['quarantine_release_message_response_data'] def test_build_url_filter_for_get_list_entries(): """ Given: Arguments To filter with. When: The function builds a URL filter from these arguments. Then: We check that the URL filter matches what the command asks for. """ from CiscoEmailSecurity import build_url_filter_for_get_list_entries res = build_url_filter_for_get_list_entries({"list_type": "safelist", "view_by": "bla", "order_by": "bla"}) assert res == "?action=view&limit=20&offset=0&quarantineType=spam&orderDir=desc&viewBy=bla&orderBy=bla" def test_list_entries_get_command(requests_mock): """ Given: Arguments for command - list_entries_get. When: The API gives us results according to the arguments we sent. Then: We check that what is in context (outputs, outputs_prefix) is what should be according to the arguments we sent to the API. """ from CiscoEmailSecurity import list_entries_get_command requests_mock.post("https://ciscoemailsecurity/sma/api/v2.0/login", json=test_data['data_for_login']) requests_mock.get("https://ciscoemailsecurity/sma/api/v2.0/quarantine/safelist", json=test_data['get_list_entries_response']) client = Client({"credentials": {"identifier": "a", "password": "b"}, "base_url": "https://ciscoemailsecurity/", "insecure": False, "proxy": False, "timeout": "2000"}) res = list_entries_get_command(client, {"list_type": "safelist", "limit": "25", "order_by": "recipient", "view_by": "recipient"}) assert res.outputs == test_data['get_list_entries_context'] assert res.outputs_prefix == 'CiscoEmailSecurity.ListEntry.Safelist' assert res.outputs_key_field == 'Safelist' def test_build_request_body_for_add_list_entries(): """ Given: Arguments To flirt with. When: The function builds a request body from these arguments. Then: We check that the request body matches what the command asks for. """ from CiscoEmailSecurity import build_request_body_for_add_list_entries res_request_body = build_request_body_for_add_list_entries({"list_type": "safelist", "action": "add", "recipient_addresses": "user.com,user.com", "sender_list": "acme.com", "view_by": "recipient"}) assert res_request_body == {"action": "add", "quarantineType": "spam", "viewBy": "recipient", "recipientAddresses": ["user.com", "user.com"], "senderList": ["acme.com"]} def test_list_entries_add_command(requests_mock): """ Given: Arguments for command - list_entries_add. When: The API gives us results according to the arguments we sent. Then: We check that what is in context (outputs, outputs_prefix) is what should be according to the arguments we sent to the API. """ from CiscoEmailSecurity import list_entries_add_command requests_mock.post("https://ciscoemailsecurity/sma/api/v2.0/login", json=test_data['data_for_login']) requests_mock.post("https://ciscoemailsecurity/sma/api/v2.0/quarantine/safelist", json=test_data['add_list_entries_response']) client = Client({"credentials": {"identifier": "a", "password": "b"}, "base_url": "https://ciscoemailsecurity/", "insecure": False, "proxy": False, "timeout": "2000"}) res = list_entries_add_command(client, {"list_type": "safelist", "action": "add", "limit": "25", "recipient_addresses": "user.com,user.com", "sender_list": "acme.com", "view_by": "recipient"}) assert res.readable_output == test_data['add_list_entries_context'] assert res.outputs_prefix == 'CiscoEmailSecurity.listEntry.Safelist' assert res.outputs_key_field == 'acme.com' def test_build_request_body_for_delete_list_entries(): """ Given: Arguments To flirt with. When: The function builds a request body from these arguments. Then: We check that the request body matches what the command asks for. """ from CiscoEmailSecurity import build_request_body_for_delete_list_entries res_request_body = build_request_body_for_delete_list_entries({"list_type": "safelist", "sender_list": "acme.com", "view_by": "recipient"}) assert res_request_body == {"quarantineType": "spam", "viewBy": "recipient", "senderList": ["acme.com"]} def test_list_entries_delete_command(requests_mock): """ Given: Arguments for command - list_entries_add. When: The API gives us results according to the arguments we sent. Then: We check that what is in context (outputs, outputs_prefix) is what should be according to the arguments we sent to the API. """ from CiscoEmailSecurity import list_entries_delete_command requests_mock.post("https://ciscoemailsecurity/sma/api/v2.0/login", json=test_data['data_for_login']) requests_mock.delete("https://ciscoemailsecurity/sma/api/v2.0/quarantine/safelist", json=test_data['delete_list_entries_response']) client = Client({"credentials": {"identifier": "a", "password": "b"}, "base_url": "https://ciscoemailsecurity/", "insecure": False, "proxy": False, "timeout": "2000"}) res = list_entries_delete_command(client, {"list_type": "safelist", "sender_list": "acme.com", "view_by": "recipient"}) assert res.readable_output == test_data['delete_list_entries_context'] assert res.outputs_prefix == 'CiscoEmailSecurity.listEntry.Safelist' assert res.outputs_key_field == 'acme.com'