Skip to content

Add email.mailfrom.address to email fields #2351

@mbudge

Description

@mbudge

There is an ecs field for email.from.address which is the From field in the email header.

The mailfrom field in the smtp header is a field useful for detecting email spoofing.

Please add email.mailfrom.address to ecs. Also update the mimecast integration to extract the headerFrom field from the inbound Acc logs.

Metadata

Metadata

Assignees

Labels

enhancementNew feature or request

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions