Views:
Important
Important
This data source query method is no longer available after February 2, 2026. For more information on the currently available data sources for use in XDR Data Explorer queries, go to https://trendmicro.github.io/tm-v1-schema/pages/index.
Field Name
Type
General Field
Description
Example
Products
actResult
  • dynamic
-
The action result
  • Success
  • Collaboration Sensor
actionName
  • string
-
The user or service action
  • UserLoggedIn
  • Collaboration Sensor
applicationId
  • string
-
The application ID
  • 11111111-1111-1111-1111-111111111111
  • Collaboration Sensor
attachmentFileHashSha256s
  • dynamic
  • FileSHA2
The SHA-256 hash of the email attachment
  • 0570dfd156ee00cb7bc2a94998157cb3a29292b9e9feed82d4b6c7d2c6bdd9d4
  • 2d96ebbbc5a5687b0f18fd5620e4e5489d49a877430146bbca447fabe9c47a6e
  • 20d27422610967122439735cbcb48e4382a16e94a8b29c068e6b7d0e40466427
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
attachmentFileHashes
  • dynamic
  • FileSHA1
The SHA-1 hash of the email attachment
  • acedb7898338a46f38d148d1d0456e644576d41b
  • ea6fcc4c0c1f10d71742b29e98a977d995473dd1
  • 03d8fb85556edf397d8afcafc0b13f11ecbde50c
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
attachmentFileName
  • dynamic
  • FileName
The file name of the email attachment
  • image001.png
  • image002.png
  • image003.png
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
attachmentFileTlshes
  • dynamic
-
The TLSH hash detected by Trend Micro Anti-Spam Engine
-
  • Trend Micro Email Security
  • Trend Micro Cloud App Security
  • Email Sensor
attachmentMd5
  • dynamic
  • FileMD5
The MD5 hash of the email attachment
  • 003fa299ab119219596f952c68029810
  • 03aeabf6a745cb627ee29c05a22e58cb
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
attachmentSha1
  • dynamic
  • FileSHA1
The SHA-1 hash of the email attachment
  • 03d8fb85556edf397d8afcafc0b13f11ecbde50c
  • 056a2975edffe7188c03c324ae4335f9380b57e3
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
attachmentSha256
  • dynamic
  • FileSHA2
The SHA-256 hash of the email attachment
  • 29d72af5608ee5eade7c4346d3c32dfcc6b54f8fb43d977ff0306ad68b255a01
  • cb0628092ddea96bb040221b5c793dbbb792a67d0621bdfba170c07374d85801
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
attachmentSize
  • dynamic
-
The attachment file size
-
  • Trend Micro Email Security
  • Trend Micro Cloud App Security
  • Email Sensor
attachmentSource
  • dynamic
-
The attachment source
  • TMASE
  • PRODUCT
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
attachmentTlsh
  • dynamic
-
The TLSH hash detected by Trend Micro Anti-Spam Engine
  • 0FE18E0807B75799EF3ADD7A98D62411FEB31DAB419C913C058068A3A6B33BD114EA39
  • 7C31C9827A71A905CC6B0A73B10FE80C06F01E814AA396347F8B6F979690E9C3D75147
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
attachmentUrls
  • dynamic
-
The URLs and URL sources extracted from the email attachment
-
  • Trend Micro Email Security
  • Email Sensor
clientIp
  • string
  • IPv4
  • IPv6
The client IP
  • 10.10.10.10
  • Collaboration Sensor
cloudStorageId
  • string
-
The file or folder location ID
  • 11111111-1111-1111-1111-111111111111
  • Collaboration Sensor
cloudStorageName
  • string
-
The file or folder URL
  • https://test.trendmicro.com/sites/123
  • Collaboration Sensor
correlationId
  • string
-
The correlation ID
  • 11111111-1111-1111-1111-111111111111
  • Collaboration Sensor
eventId
  • int
-
The event ID
  • 1 - MESSAGING_EMAIL_META
  • 2 - MESSAGING_COLLABORATION_ACTIVITY
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
  • Collaboration Sensor
eventName
  • string
-
The event type
  • COLLABORATION_ACTIVITY
  • Collaboration Sensor
eventSubName
  • string
-
The event type sub-name
  • Audit.Exchange
  • Audit.Sharepoint
  • Audit.General
  • Collaboration Sensor
eventTime
  • real
-
The time the agent detected the event
  • 1657135700000
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
extraInfo
  • dynamic
-
The additional information about the sharing action
  • <ClientType>SPHomePagesWeb</ClientType>
  • Collaboration Sensor
fileExt
  • string
-
The file extension (If the object is a folder, there is no value for this field.)
  • jpg
  • Collaboration Sensor
fileName
  • string
  • FileName
The file or folder name
  • test.pdf
  • Collaboration Sensor
filterRiskLevel
  • string
-
The top-level risk level of the event
  • info
  • low
  • medium
  • All products
groupId
  • string
-
The group ID for the management scope filter
  • 11111111-1111-1111-1111-111111111111
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
isExternalAccess
  • bool
-
Whether the cmdlet was run by an external user (True=external user, False=internal user in your organization)
  • true
  • Collaboration Sensor
isSensitiveInfo
  • bool
-
Whether the event contains sensitive information
  • true
  • Collaboration Sensor
logReceivedTime
  • long
-
The time when the XDR log was received
  • 1656324260000
  • All products
mExternalUid
  • string
-
The unique ID of the email
  • 11111111-1111-1111-1111-111111111111
  • Trend Micro Cloud App Security
  • Email Sensor
mailAttachmentHash
  • string
  • FileMD5
The hash value of the email attachment
  • 02ab50ee0bccadb43d6cc504928f2ff2
  • 0a0f335fb04f1acebb7500d5358321c0
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
mailBccAddresses
  • dynamic
  • EmailRecipient
The BCC address in the email header
  • sample_email@trendmicro.com
  • Trend Micro Email Security
  • Trend Micro Cloud App Security
  • Email Sensor
mailCacheId
  • string
-
The internal email cache ID to identify emails in the same group mails
  • <sample_email@trendmicro.com>
  • Trend Micro Cloud App Security
  • Email Sensor
mailCcAddresses
  • dynamic
  • EmailRecipient
The CC address in the email header
  • <sample_email@trendmicro.com>
  • sample_email@trendmicro.com
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
mailDirection
  • int
-
The email traffic direction
  • 1
  • 3
  • 25
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
mailEurekaRuleIds
  • dynamic
-
The list of rule IDs scanned by Eureka and detected by Trend Micro Anti-Spam Engine
  • 661030
  • 661230
  • 661267
  • Trend Micro Email Security
  • Trend Micro Cloud App Security
  • Email Sensor
mailFeatureId
  • dynamic
-
The email protocol detected by Trend Micro Anti-Spam Engine
-
  • Trend Micro Email Security
  • Trend Micro Cloud App Security
  • Email Sensor
mailFolder
  • string
-
The email folder name
  • Inbox
  • Bandeja de entrada
  • Sent Items
  • Trend Micro Cloud App Security
  • Email Sensor
mailFromAddresses
  • dynamic
  • EmailSender
The From address in the email header
  • sample_email@trendmicro.com
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
mailHeaderHash
  • string
-
The email header hash detected by Trend Micro Anti-Spam Engine
  • 43f8bfc02d8f78f069c254bc17eba80b
  • aa5d16ca145f91471e482d235843aac5
  • ad8776382ea4b7cffd0961c70223162e
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
mailHelo
  • string
-
The HELO command detected by Trend Micro Anti-Spam Engine
  • HELO inpost.tmes.trendmicro.com
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
mailMetaText
  • string
-
The postman meta text detected by Trend Micro Anti-Spam Engine
  • Trend Micro Email Security
  • Email Sensor
mailMetaTraceId
  • string
-
The trace ID generated by Trend Micro Feedback Engine
  • Trend Micro Email Security
  • Email Sensor
mailMsgId
  • string
  • EmailMessageID
The email ID
  • <sample-id@trendmicro.com>
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
mailMsgSubject
  • string
  • EmailSubject
The email subject
  • Your daily briefing
  • Security alert for DeleteSecurityGroup on Account 549918006255 in Region: ap-southeast-1
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
mailReplyToAddresses
  • dynamic
-
The Reply To address detected by Trend Micro Anti-Spam Engine
  • sample_email@trendmicro.com
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
mailRuleId
  • dynamic
-
The rule ID of the matched rule detected by Trend Micro Anti-Spam Engine
  • 42003
  • 148036
  • 148140
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
mailScore
  • string
-
The score assigned to the email by Trend Micro Anti-Spam Engine
-
  • Trend Micro Email Security
  • Trend Micro Cloud App Security
  • Email Sensor
mailSenderIp
  • string
-
The email sender IP address
  • 10.10.10.10
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
mailSmtpFromAddresses
  • dynamic
-
The sender email address
  • sample_email@trendmicro.com
  • Trend Micro Email Security
  • Email Sensor
mailSmtpOriginalRecipients
  • dynamic
-
The original email recipients in the SMTP envelope
  • sample_email@trendmicro.com
  • Trend Micro Email Security
  • Email Sensor
mailSmtpRecipients
  • dynamic
-
The email recipients in the SMTP envelope after scanning
  • sample_email@trendmicro.com
  • Trend Micro Email Security
  • Email Sensor
mailSmtpTls
  • string
-
The SMTP TLS version number
  • TLS 1.2
  • TLS 1.3
  • noTLS
  • Trend Micro Email Security
  • Email Sensor
mailSourceDomain
  • string
-
The email domain of the sender
  • example.com
  • Trend Micro Cloud App Security
  • Email Sensor
mailTagHash
  • string
-
The email tag hash detected by Trend Micro Anti-Spam Engine
  • 9ce01ebc63f408264876646e20905349
  • cf679dc99042b781106cbaccd4045ed3
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
mailTagHashRawSignature
  • string
-
The raw signature hash of the email
  • PGh0bWw+PGhlYWQ+PG1ldGEgaHR0cC1lcXVpdj0gY29udGVudD0gY2hhcnNldD0gPjxtZXRhIG5hbWU9IGNvbnRlbnQ9ID48c3R5bGU+PCEtLS0tPjwvc3R5bGU+PC9oZWFkPjxib2R5IGxhbmc9IGxpbms9IHZsaW5rPSBzdHlsZT0gPjxkaXYgY2xhc3M9ID48cCBjbGFzcz0gPjxURVhUPjwvcD48L2Rpdj48L2JvZHk+PC9odG1sPg==
  • PGh0bWw+PGhlYWQ+PG1ldGEgaHR0cC1lcXVpdj0gY29udGVudD0gY2hhcnNldD0gPjwvaGVhZD48Ym9keT48VEVYVD48L2JvZHk+PC9odG1sPg==
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
mailTextHash
  • string
-
The email text hash detected by Trend Micro Anti-Spam Engine
  • 221bab3766f6d2a2c6fcc37056511d53
  • f26f3a415103ea083ac49be6bb60f337
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
mailThreatType
  • string
-
The type of email detected by Trend Micro Anti-Spam Engine
  • suspected
  • suspected,
  • suspected, phishing
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
mailToAddresses
  • dynamic
  • EmailRecipient
The Mail To address in the email header
  • sample_email@trendmicro.com
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
mailUrlHash
  • string
-
The email URL hash detected by Trend Micro Anti-Spam Engine
  • ca52197d96e4a00ce19eaf34b20c8937
  • ad50776a891bead6bf222e2b7be17724
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
mailUrlsOriginalLink
  • dynamic
-
The original URL extracted from the email content
  • https://aka.ms/JoinTeamsMeeting
  • http://go.microsoft.com/fwlink/p/?LinkID=12345
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
mailUrlsRealLink
  • dynamic
  • URL
The URL extracted from the email content
  • https://aka.ms/JoinTeamsMeeting
  • http://go.microsoft.com/fwlink/p/?LinkID=12345
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
mailUrlsVisibleLink
  • dynamic
  • URL
The URL extracted from the email content
  • Unsubscribe
  • Android
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
mailUserAgent
  • string
-
The user agent
  • Mutt/1.4.2.2i
  • Heirloom mailx 12.5 7/5/10
  • Trend Micro Email Security
  • Trend Micro Cloud App Security
  • Email Sensor
mailWantedHeaderName
  • dynamic
-
The WantedHeader key name detected by Trend Micro Anti-Spam Engine
  • CC
  • X-TM-Product-Ver
  • Received
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
mailWantedHeaderValue
  • dynamic
-
The WantedHeader key value detected by Trend Micro Anti-Spam Engine
  • cloud-app-security-5.0
  • BCL:0;
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
mailWholeHeader
  • dynamic
-
The name and email address of the sender in the From header detected by Trend Micro Anti-Spam Engine
  • <sample_email@trendmicro.com>
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
mailXMailer
  • string
-
The X-Mailer header of the email
  • Microsoft Outlook 16.0
  • Microsoft CDO for Windows 2000
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
mailbox
  • string
-
The primary email address
  • sample_email@trendmicro.com
  • Trend Micro Cloud App Security
  • Email Sensor
msgUuid
  • string
-
The internal email UUID to identify each email message
  • 11111111-1111-1111-1111-111111111111
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
msgUuidChain
  • string
-
The internal UUID chain for each email in Trend Micro Feedback Engine
  • 11111111-1111-1111-1111-111111111111;00000000-0000-0000-0000-000000000000
  • Trend Micro Email Security
  • Email Sensor
orgId
  • string
-
The organization ID
  • 11111111-1111-1111-1111-111111111111
  • Trend Micro Cloud App Security
  • Email Sensor
orgName
  • string
-
The tenant name
  • test.trendmicro.com
  • Collaboration Sensor
originatingServer
  • string
-
The server where the operation originated
  • TY0PR03MB6449 (15.20.5746.023)
  • Collaboration Sensor
parameters
  • string
-
The names and values of all parameters used in the cmdlet identified in the Operations property
  • [{"Name": "AlwaysDeleteOutlookRulesBlob","Value": "False"},{"Name" : "Force","Value": "False"}]
  • Collaboration Sensor
pname
  • string
-
The internal product code (deprecated)
  • 733
  • 742
  • TMEMS
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
policyTreePath
  • string
-
The policy tree path (endpoint only)
  • policyname1/policyname2/policyname3
  • All products
principalName
  • string
  • UserAccount
The User Principal Name
  • sample_email@trendmicro.com
  • Collaboration Sensor
productCode
  • string
-
The product code of the product that sent the log
  • sca
  • sem
  • All products
recordType
  • int
-
The operation type
  • 1
  • 2
  • Collaboration Sensor
scanTs
  • string
-
The time the email was scanned
  • 1657135700000
  • Trend Micro Cloud App Security
  • Email Sensor
  • Trend Micro Email Security
scanType
  • string
-
The manual or real-time scan type
  • realtime_mailmeta-exchange
  • realtime_mailmeta-gmail
  • gateway_mailmetadata
  • gateway_realtime_accepted_mail_traffic
  • Trend Micro Cloud App Security
  • Trend Micro Email Security
  • Email Sensor
service
  • string
-
The Microsoft 365 service where the activity occurred
  • SecurityComplianceCenter
  • AzureActiveDirectory
  • SharePoint
  • Collaboration Sensor
tags
  • dynamic
-
The detected technique ID based on the alert filter
  • MITREV9.T1057
  • MITREV9.T1059.003
  • XSAE.F2924
  • All products
target
  • string
-
The object accessed by a user or application
  • APCPR000000.PROD.OUTLOOK.COM/Microsoft Exchange Hosted
  • Organizations/test.trendmicro.com/test\\testRule001
  • Collaboration Sensor
targetType
  • string
-
The type of object that was accessed or modified
  • File
  • Collaboration Sensor
userAgent
  • string
-
The user agent
  • Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36
  • Collaboration Sensor
userSessionId
  • string
-
The user session ID
  • 11111111-1111-1111-1111-111111111111
  • Collaboration Sensor
userType
  • string
-
The user type
  • Regular
  • Reserved
  • Admin
  • Collaboration Sensor
uuid
  • string
-
The unique key of the log entry
  • 11111111-1111-1111-1111-111111111111
  • All products