Cisco Secure Email Gateway Mail Logs
Cisco Secure Email Gateway (formerly ESA, AsyncOS 16.x) text mail_logs pushed over syslog from a virtual gateway with one Management interface and one public listener: internet mail for contoso.example users and outbound mail relayed from two internal Exchange hosts, with the raw syslog line in event.original and the fields the Elastic cisco_secure_email_gateway integration extracts from it. About 95,000 lines a day follow the working day of 100 internal users in UTC. Recurring episodes show one internal user sending three large messages to their own freemail mailbox within 40 minutes, a likely exfiltration.
Quick Start
uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
--path generators/email-cisco-secure-email-gateway/generator.yml \
--id seg \
--live-mode trueEvent Types
| Event ID | Description | Frequency | Category |
|---|---|---|---|
| New SMTP ICID | New SMTP ICID ... address ... reverse dns host ... verified | 4.69% of lines | connection |
| ICID SG | ICID ... ACCEPT SG / RELAY SG / REJECT SG ... SBRS | 4.69% of lines | connection policy |
| ICID close | ICID ... close | 4.69% of lines | connection |
| Start MID | Start MID ... ICID | 4.23% of lines | message |
| MID From | MID ... ICID ... From: | 4.23% of lines | message |
| MID RID To | MID ... ICID ... RID n To: | 4.91% of lines | message |
| MID Message-ID | MID ... Message-ID | 4.23% of lines | message |
| MID Subject | MID ... Subject | 4.23% of lines | message |
| MID ready | MID ... ready <bytes> bytes from | 4.23% of lines | message |
| MID per-recipient policy | MID ... matched all recipients for per-recipient policy DEFAULT | 4.23% of lines | policy |
| MID SPF | MID ... SPF: mailfrom identity ... Pass | 2.18% of lines | authentication |
| MID DKIM | MID ... DKIM: pass signature verified | 2.18% of lines | authentication |
| MID DMARC | MID ... DMARC: ... DMARC pass | 2.18% of lines | authentication |
| MID CASE interim | MID ... interim verdict using engine: CASE spam ... | 2.41% of lines | anti-spam |
| MID CASE final | MID ... using engine: CASE spam ... / GRAYMAIL positive | 2.90% of lines | anti-spam |
| MID AV interim | MID ... interim AV verdict using Sophos CLEAN | 4.23% of lines | anti-virus |
| MID antivirus negative | MID ... antivirus negative | 4.23% of lines | anti-virus |
| MID antivirus positive | MID ... antivirus positive | <0.01% of lines | anti-virus |
| Message aborted | Message aborted MID ... Dropped by antivirus | <0.01% of lines | anti-virus |
| MID attachment | MID ... attachment | 1.87% of lines | content |
| MID Outbreak Filters | MID ... Outbreak Filters: verdict negative | 2.40% of lines | outbreak filters |
| MID queued | MID ... queued for delivery | 4.23% of lines | message |
| EUQ Tagging | EUQ: Tagging MID ... for quarantine | 0.23% of lines | quarantine |
| RPC Delivery start | RPC Delivery start RCID ... MID ... | 0.23% of lines | quarantine |
| EUQ Quarantined | EUQ: Quarantined MID | 0.23% of lines | quarantine |
| RPC Message done | RPC Message done RCID ... MID | 0.23% of lines | quarantine |
| New SMTP DCID | New SMTP DCID ... interface ... address | 4.35% of lines | delivery |
| Delivery start | Delivery start DCID ... MID ... to RID [...] | 4.35% of lines | delivery |
| Message done | Message done DCID ... MID ... to RID [...] | 4.31% of lines | delivery |
| MID RID Response | MID ... RID [...] Response '...' | 4.31% of lines | delivery |
| Bounced | Bounced: DCID ... MID ... to RID n - 5.1.0 - ... | 0.04% of lines | delivery |
| DCID close | DCID ... close | 4.35% of lines | delivery |
| Message finished | Message finished MID ... done | 4.23% of lines | message |
Realism Features
- About 95,000 lines a day in UTC, with about 1,740 outbound and 2,300 inbound messages and 435 rejected connections. Total volume follows the working day of internal users: about 2,050 lines an hour at night, rising from 06:00 to about 6,500 an hour between 09:00 and 15:00, then falling after 16:00 to a tail until 19:00; internet mail is higher between 06:00 and 17:00 and continues at night. Users, their weights and working hours are fixed, mail volume per user changes from day to day only by random variation, and weekends look like weekdays.
- 100 internal users each have an activity weight, their own working hours in UTC and a personal mailbox at one of the freemail providers. Outbound mail comes from users in proportion to their weight, mostly within their own working hours, as single messages and series of 2-5 messages to the same recipients; about 2% of recipients are mistyped and hard-bounce. Inbound mail brings partner and freemail correspondents, newsletters marked as graymail, spam quarantined by CASE (about 210 messages a day), low-reputation connections rejected by the blocked-list sender group and a few virus drops a day. Rates and shares are synthetic, not vendor-measured.
- Every user now and then mails their own personal mailbox, singly or in quick series: about 165 such messages a day, about 23 of them 8 MB or more. A group of 22 users does this one to six times a day, the others a few times a week. Per 4 days, two large messages to the own mailbox within 40 minutes occur 5-12 times, and three or more large messages from one sender to other recipients within 40 minutes 64-100 times. Three large messages to the own mailbox within 46 minutes never occur outside episodes, a slightly wider empty margin than a real gateway would show.
- With anomaly_mode true each episode adds its own three large messages to a personal mailbox, so counts of large personal mail are about three per episode higher than in background only, while the total line count is the same in both modes; at intervals of a few hours closely spaced large messages per sender become noticeably more frequent. The gateway logs no content beyond attachment names, so the chain shows volume and destination, not intent.
- Each record keeps the raw syslog line and the fields the integration's grok patterns extract: MID, ICID, DCID, RID, sender and recipient addresses, read bytes, connection and message status, and scanning engine verdicts. Structured fields are what Elastic integration 1.29.3 extracts; its connection pattern matches only the Management interface, hence the single interface. Sender-group, antivirus, attachment, quarantine and bounce lines keep only email.message_id or the message text, as the integration leaves them, and Elastic agent fields are omitted.
- No complete raw capture of an AsyncOS 16.x appliance was available: line grammar follows the AsyncOS 16.5 Logging chapter examples and the Elastic integration fixtures, the RELAY SG ... SBRS rfc1918 line follows Cisco TechNote 214631, and the REJECT SG BLOCKED_LIST line applies the documented ACCEPT SG grammar to the default blocked sender group.
- Syslog timestamps have one-second resolution and no year, @timestamp is UTC with .000 milliseconds, and the priority is always <166> (local4.info), as in the integration fixtures. Lines the appliance writes at the same instant are spread over consecutive seconds: connection and sender-group lines share a second in 42% of connections and are at most 6 s apart in 99%. A message takes a median 28 s from Start MID to Message finished (10% under 13 s, 10% over 57 s), longer than on a real gateway, and longer at night (about 45 s) than by day (about 23 s).
- Not covered: TLS, SMTP authentication, per-connection message reuse, delayed (soft-bounce) delivery, DLP, AMP, URL filtering, message filters, Subject with double quotes and log levels other than Info. SPF, DKIM and DMARC pass for legitimate inbound senders and are not logged for spam senders.
Sample Output
{
"@timestamp": "2026-09-01T11:55:22.000Z",
"cisco_secure_email_gateway": {
"log": {
"category": {
"name": "mail_logs"
},
"host": "esa-01.contoso.example",
"message": "MID 74652742 ready 9721387 bytes from \u003cf.sergeeva@contoso.example\u003e",
"read_bytes": 9721387
}
},
"ecs": {
"version": "8.17.0"
},
"email": {
"from": {
"address": [
"f.sergeeva@contoso.example"
]
},
"message_id": "74652742"
},
"event": {
"dataset": "cisco_secure_email_gateway.log",
"kind": "event",
"original": "\u003c166\u003eSep 1 11:55:22 esa-01.contoso.example mail_logs: Info: MID 74652742 ready 9721387 bytes from \u003cf.sergeeva@contoso.example\u003e",
"timezone": "UTC"
},
"log": {
"level": "info",
"syslog": {
"priority": 166
}
},
"tags": [
"preserve_original_event"
]
}Parameters
| Parameter | Default | Description |
|---|---|---|
| anomaly_mode | true | Add the recurring large-mail episode; false produces background only |
| anomaly_interval_hours | 24 | Hours from one episode start to the next due time, 1 to 8,760 |
| host_name | esa-01.contoso.example | Gateway host name in the syslog header |
| interface_ip | 10.20.30.25 | Address of the Management interface |
| internal_domain | contoso.example | Domain of internal users |
| relay_hosts | [exch-01.contoso.example 10.20.10.11, exch-02.contoso.example 10.20.10.12] | Internal Exchange hosts that relay outbound mail and receive inbound mail; users are assigned to them in turn |
| large_message_bytes | 8000000 | Size threshold of the episode messages; background never has three such messages to the sender's own mailbox within 40 minutes |
| max_message_bytes | 20000000 | Largest message the listener accepts |
| partner_domains | 8 domains (fabrikam.test ... wingtiptoys.test) | Partner mail domains with their MX address and base reputation (SBRS) |
| freemail_domains | [mail.example.com, webmail.example.net, inbox.example.org] | Public mailbox providers; users' personal mailboxes are spread over them in turn |
| newsletter_senders | [news@digest.example.com, noreply@events.example.net, offers@shop.example.org, updates@saas.example.com] | Bulk senders marked as graymail |
Related Generators
Microsoft Exchange Message Tracking
Exchange Server 2019 message tracking — SMTP receive/send, mailbox delivery, transport routing, shadow redundancy, anti-spam filtering, distribution group expansion, and delivery failure DSNs.
Kaspersky Secure Mail Gateway
Kaspersky Secure Mail Gateway (KSMG) ScanLogic events — anti-virus, anti-spam, anti-phishing, content filtering, mail authentication (SPF/DKIM/DMARC), KATA integration, message backup, and scan failure events in ECS-compatible JSON.
Fortinet FortiMail
FortiMail email security gateway — mail statistics, SMTP protocol events, antispam verdict (clean/spam/phishing), antivirus scanning with quarantine actions, and system administration logs.