Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
The Microsoft Sentinel Email Event normalization schema represents email delivery and inspection activity. It includes message addressing and routing details, email authentication results, delivery outcomes, and threats identified in email messages.
Use the Email Event schema to normalize records from mail servers, secure email gateways, email security services, and other systems that process or inspect email. Normalization lets you analyze these records with consistent field names and values, regardless of the source.
For more information about normalization in Microsoft Sentinel, see Normalization and the Advanced Security Information Model (ASIM).
Schema overview
The main fields of an email event describe:
- The email activity, represented by EventType and EventSubType.
- The sender and recipients, represented by EmailFromAddress, EmailToRecipients, EmailCCRecipients, and EmailBCCRecipients.
- The message, represented by fields such as EmailSubject, EmailSizeBytes, EmailFiles, and EmailUrls.
- Email authentication, represented by the SPF, DKIM, and DMARC fields.
- The delivery outcome, represented by DvcAction, EmailDeliveryLocation, EventResult, and EventResultDetails.
- Threats and inspection rules associated with the message, represented by the inspection fields.
The Dvc fields describe the reporting or inspecting system.
Parsers
Deploy and use email event parsers
Deploy ASIM parsers from the Microsoft Sentinel GitHub repository. To query all normalized email event sources, use the unifying parser _Im_EmailEvent as the table name in your query.
For more information about using ASIM parsers, see the ASIM parsers overview.
Add your own normalized parsers
When you implement custom parsers for the Email Event information model, use the following naming syntax:
ASimEmailEvent<vendor><Product>for regular parsers.vimEmailEvent<vendor><Product>for parameterized parsers.
To add custom parsers to the Email Event unifying parser, see Manage ASIM parsers.
Filter parser results
The Email Event filtering parser supports filtering parameters to improve query performance.
| Name | Type | Description |
|---|---|---|
| starttime | datetime | Filter events that started at or after this time. |
| endtime | datetime | Filter events that ended at or before this time. |
| ipaddr_has_any_prefix | dynamic | Filter events for which an IP address starts with one of the listed prefixes. |
| emailfromaddress_has_any | dynamic | Filter events for which EmailFromAddress contains one of the listed values. |
| emailrecipient_has_any | dynamic | Filter events that have one of the listed email recipients. |
| emailsubject_has_any | dynamic | Filter events for which EmailSubject contains one of the listed values. |
| emaildirection_in | dynamic | Filter events for which EmailDirection is one of the listed values. |
| emaildeliverylocation_in | dynamic | Filter events for which EmailDeliveryLocation is one of the listed values. |
| eventresult | String | Filter events for which EventResult equals the specified value. The default value, *, doesn't filter by result. |
| pack | Boolean | When set to true, pack unmapped source fields into the AdditionalFields dynamic field. The default is false. |
For example, use the following query to return inbound email sent by addresses that contain contoso.com during the last day:
_Im_EmailEvent(
starttime=ago(1d),
endtime=now(),
emailfromaddress_has_any=dynamic(['contoso.com']),
emaildirection_in=dynamic(['Inbound'])
)
Schema details
Common ASIM fields
Important
Fields common to all schemas are described in detail in ASIM common fields. Guidelines in this article override the general guidelines for a field.
Common fields with specific guidelines
All common fields
| Class | Fields |
|---|---|
| Mandatory | - EventCount - EventStartTime - EventEndTime - EventType - EventResult - EventProduct - EventVendor - EventSchema - EventSchemaVersion - Dvc |
| Recommended | - EventResultDetails - EventSeverity - EventUid - DvcIpAddr - DvcHostname - DvcDomain |
| Optional | - EventMessage - EventSubType - EventOriginalUid - EventOriginalType - EventOriginalResultDetails - EventOriginalSeverity - EventProductVersion - EventReportUrl - EventOwner - DvcDescription - DvcFQDN - DvcId - DvcInterface - DvcMacAddr - DvcOriginalAction - DvcOs - DvcOsVersion - DvcScope - DvcScopeId - DvcZone - AdditionalEntities - AdditionalFields |
| Conditional | - DvcDomainType - DvcIdType |
Email fields
Email authentication fields
| Field | Class | Type | Description |
|---|---|---|---|
| EmailSpfResult | Optional | Enumerated | The normalized Sender Policy Framework (SPF) result. Allowed values are Pass, Fail, SoftFail, Neutral, None, TemporaryError, and PermanentError. |
| EmailSpfOriginalResult | Optional | String | The SPF result as reported by the source. |
| EmailDkimDomain | Optional | String | The domain that signed the message with DomainKeys Identified Mail (DKIM). |
| EmailDkimSignature | Optional | String | The DKIM signature associated with the message. |
| EmailDkimResult | Optional | Enumerated | The normalized DKIM result. Allowed values are Pass, Fail, TemporaryError, PermanentError, and None. |
| EmailDkimOriginalResult | Optional | String | The DKIM result as reported by the source. |
| EmailDmarcResult | Optional | Enumerated | The normalized Domain-based Message Authentication, Reporting, and Conformance (DMARC) result. Allowed values are Pass, Fail, BestGuessPass, and None. |
| EmailDmarcOriginalResult | Optional | String | The DMARC result as reported by the source. |
| EmailDmarcPolicy | Optional | Enumerated | The DMARC policy applied to the email. Allowed values are Quarantine, Reject, and None. |
| EmailDmarcOverride | Optional | Enumerated | The reason the DMARC policy was overridden. Allowed values are Forwarded, LocalPolicy, MailingList, SampleOut, TrustedForwarder, and Other. |
Delivery and destination fields
Source system fields
| Field | Class | Type | Description |
|---|---|---|---|
| Src | Recommended | String | A unique identifier for the source system. |
| SrcIpAddr | Optional | IP address | The source IP address. |
| IpAddr | Alias | IP address | Alias to SrcIpAddr. |
| SrcHostname | Recommended | Hostname | The source device hostname, excluding domain information. |
| SrcDomain | Recommended | Domain | The domain of the source device. |
| SrcDomainType | Conditional | Enumerated | The type of SrcDomain. Allowed values are Windows, FQDN, and ResourceGroup. Required when SrcDomain is used. |
| SrcFQDN | Optional | FQDN | The fully qualified domain name of the source device. |
| SrcDvcId | Optional | String | The ID of the source device. |
| SrcDvcIdType | Conditional | Enumerated | The type of SrcDvcId. Allowed values are AzureResourceId, MDEid, MD4IoTid, VMConnectionId, AwsVpcId, VectraId, ForcepointId, AppGateId, and Other. Required when SrcDvcId is used. |
| SrcDvcScope | Optional | String | The cloud platform scope to which the source device belongs. |
| SrcDvcScopeId | Optional | String | The ID of the cloud platform scope to which the source device belongs. |
| SrcDeviceType | Optional | Enumerated | The source device type. |
| SrcDescription | Optional | String | A description of the source device. |
| SrcIsp | Optional | String | The internet service provider associated with the source IP address. |
| SrcGeoCountry | Optional | String | The country or region associated with the source IP address. |
| SrcGeoRegion | Optional | String | The region associated with the source IP address. |
| SrcGeoCity | Optional | String | The city associated with the source IP address. |
| SrcGeoLatitude | Optional | Real | The latitude associated with the source IP address. |
| SrcGeoLongitude | Optional | Real | The longitude associated with the source IP address. |
Source user fields
| Field | Class | Type | Description |
|---|---|---|---|
| SrcUserName | Optional | String | The source user's name. |
| User | Alias | String | Alias to SrcUserName. |
| SrcUserUpn | Recommended | String | The source user's User Principal Name (UPN). |
| SrcUserId | Optional | String | A machine-readable identifier for the source user. |
| SrcUserIdType | Optional | Enumerated | The type of SrcUserId. Allowed values are SID, UID, AADID, OktaId, AWSId, PUID, SalesforceId, VectraUserId, MD4IoTid, and Other. |
| SrcUsernameType | Optional | Enumerated | The type of the value in SrcUserName. |
| SrcUserScope | Optional | String | The scope in which the source user is defined. |
| SrcUserScopeId | Optional | String | The ID of the scope in which the source user is defined. |
Inspection fields
The following fields describe the rule, threat, or indicator associated with email inspection.
| Field | Class | Type | Description |
|---|---|---|---|
| RuleName | Optional | String | The name or ID of the inspection rule. |
| RuleNumber | Optional | Integer | The numeric ID of the inspection rule. |
| Rule | Alias | String | Alias to RuleName. |
| RuleDescription | Optional | String | A description of the inspection rule. |
| IndicatorType | Optional | Enumerated | The type of indicator identified in the email event. |
| IndicatorAssociation | Optional | Enumerated | The association between the indicator and the email event. |
| ThreatId | Optional | String | The ID of the threat identified in the email. |
| ThreatName | Optional | String | The name of the threat identified in the email. |
| ThreatCategory | Optional | String | The normalized threat category. |
| ThreatOriginalCategory | Optional | String | The threat category as reported by the source. |
| ThreatRiskLevel | Optional | RiskLevel (Integer) | The normalized threat risk level, from 0 through 100. |
| ThreatOriginalRiskLevel | Optional | String | The threat risk level as reported by the source. |
| ThreatConfidence | Optional | ConfidenceLevel (Integer) | The normalized confidence level, from 0 through 100. |
| ThreatOriginalConfidence | Optional | String | The threat confidence as reported by the source. |
| ThreatIsActive | Optional | Boolean | Indicates whether the identified threat is active. |
| ThreatFirstReportedTime | Optional | Datetime | The first time the threat was reported. |
| ThreatLastReportedTime | Optional | Datetime | The last time the threat was reported. |
| ThreatIpAddr | Optional | IP address | An IP address associated with the identified threat. |
| ThreatField | Conditional | Enumerated | The field for which the threat was identified. |
| AttackTactics | Optional | String | The MITRE ATT&CK tactics associated with the email event. |
| AttackTechniques | Optional | String | The MITRE ATT&CK techniques associated with the email event. |
| AttackRemediationSteps | Optional | String | Recommended steps to remediate the identified attack or threat. |
Schema updates
Version 1.0.0 is the initial release of the Email Event schema.