Hub
Email

Cisco Secure Email Gateway Mail Logs

Cisco Secure Email Gateway (formerly ESA, AsyncOS 16.x) text mail_logs pushed over syslog from a virtual gateway with one Management interface and one public listener: internet mail for contoso.example users and outbound mail relayed from two internal Exchange hosts, with the raw syslog line in event.original and the fields the Elastic cisco_secure_email_gateway integration extracts from it. About 95,000 lines a day follow the working day of 100 internal users in UTC. Recurring episodes show one internal user sending three large messages to their own freemail mailbox within 40 minutes, a likely exfiltration.

Quick Start

uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
  --path generators/email-cisco-secure-email-gateway/generator.yml \
  --id seg \
  --live-mode true

Event Types

Event IDDescriptionFrequencyCategory
New SMTP ICIDNew SMTP ICID ... address ... reverse dns host ... verified4.69% of linesconnection
ICID SGICID ... ACCEPT SG / RELAY SG / REJECT SG ... SBRS4.69% of linesconnection policy
ICID closeICID ... close4.69% of linesconnection
Start MIDStart MID ... ICID4.23% of linesmessage
MID FromMID ... ICID ... From:4.23% of linesmessage
MID RID ToMID ... ICID ... RID n To:4.91% of linesmessage
MID Message-IDMID ... Message-ID4.23% of linesmessage
MID SubjectMID ... Subject4.23% of linesmessage
MID readyMID ... ready <bytes> bytes from4.23% of linesmessage
MID per-recipient policyMID ... matched all recipients for per-recipient policy DEFAULT4.23% of linespolicy
MID SPFMID ... SPF: mailfrom identity ... Pass2.18% of linesauthentication
MID DKIMMID ... DKIM: pass signature verified2.18% of linesauthentication
MID DMARCMID ... DMARC: ... DMARC pass2.18% of linesauthentication
MID CASE interimMID ... interim verdict using engine: CASE spam ...2.41% of linesanti-spam
MID CASE finalMID ... using engine: CASE spam ... / GRAYMAIL positive2.90% of linesanti-spam
MID AV interimMID ... interim AV verdict using Sophos CLEAN4.23% of linesanti-virus
MID antivirus negativeMID ... antivirus negative4.23% of linesanti-virus
MID antivirus positiveMID ... antivirus positive<0.01% of linesanti-virus
Message abortedMessage aborted MID ... Dropped by antivirus<0.01% of linesanti-virus
MID attachmentMID ... attachment1.87% of linescontent
MID Outbreak FiltersMID ... Outbreak Filters: verdict negative2.40% of linesoutbreak filters
MID queuedMID ... queued for delivery4.23% of linesmessage
EUQ TaggingEUQ: Tagging MID ... for quarantine0.23% of linesquarantine
RPC Delivery startRPC Delivery start RCID ... MID ...0.23% of linesquarantine
EUQ QuarantinedEUQ: Quarantined MID0.23% of linesquarantine
RPC Message doneRPC Message done RCID ... MID0.23% of linesquarantine
New SMTP DCIDNew SMTP DCID ... interface ... address4.35% of linesdelivery
Delivery startDelivery start DCID ... MID ... to RID [...]4.35% of linesdelivery
Message doneMessage done DCID ... MID ... to RID [...]4.31% of linesdelivery
MID RID ResponseMID ... RID [...] Response '...'4.31% of linesdelivery
BouncedBounced: DCID ... MID ... to RID n - 5.1.0 - ...0.04% of linesdelivery
DCID closeDCID ... close4.35% of linesdelivery
Message finishedMessage finished MID ... done4.23% of linesmessage

Realism Features

  • About 95,000 lines a day in UTC, with about 1,740 outbound and 2,300 inbound messages and 435 rejected connections. Total volume follows the working day of internal users: about 2,050 lines an hour at night, rising from 06:00 to about 6,500 an hour between 09:00 and 15:00, then falling after 16:00 to a tail until 19:00; internet mail is higher between 06:00 and 17:00 and continues at night. Users, their weights and working hours are fixed, mail volume per user changes from day to day only by random variation, and weekends look like weekdays.
  • 100 internal users each have an activity weight, their own working hours in UTC and a personal mailbox at one of the freemail providers. Outbound mail comes from users in proportion to their weight, mostly within their own working hours, as single messages and series of 2-5 messages to the same recipients; about 2% of recipients are mistyped and hard-bounce. Inbound mail brings partner and freemail correspondents, newsletters marked as graymail, spam quarantined by CASE (about 210 messages a day), low-reputation connections rejected by the blocked-list sender group and a few virus drops a day. Rates and shares are synthetic, not vendor-measured.
  • Every user now and then mails their own personal mailbox, singly or in quick series: about 165 such messages a day, about 23 of them 8 MB or more. A group of 22 users does this one to six times a day, the others a few times a week. Per 4 days, two large messages to the own mailbox within 40 minutes occur 5-12 times, and three or more large messages from one sender to other recipients within 40 minutes 64-100 times. Three large messages to the own mailbox within 46 minutes never occur outside episodes, a slightly wider empty margin than a real gateway would show.
  • With anomaly_mode true each episode adds its own three large messages to a personal mailbox, so counts of large personal mail are about three per episode higher than in background only, while the total line count is the same in both modes; at intervals of a few hours closely spaced large messages per sender become noticeably more frequent. The gateway logs no content beyond attachment names, so the chain shows volume and destination, not intent.
  • Each record keeps the raw syslog line and the fields the integration's grok patterns extract: MID, ICID, DCID, RID, sender and recipient addresses, read bytes, connection and message status, and scanning engine verdicts. Structured fields are what Elastic integration 1.29.3 extracts; its connection pattern matches only the Management interface, hence the single interface. Sender-group, antivirus, attachment, quarantine and bounce lines keep only email.message_id or the message text, as the integration leaves them, and Elastic agent fields are omitted.
  • No complete raw capture of an AsyncOS 16.x appliance was available: line grammar follows the AsyncOS 16.5 Logging chapter examples and the Elastic integration fixtures, the RELAY SG ... SBRS rfc1918 line follows Cisco TechNote 214631, and the REJECT SG BLOCKED_LIST line applies the documented ACCEPT SG grammar to the default blocked sender group.
  • Syslog timestamps have one-second resolution and no year, @timestamp is UTC with .000 milliseconds, and the priority is always <166> (local4.info), as in the integration fixtures. Lines the appliance writes at the same instant are spread over consecutive seconds: connection and sender-group lines share a second in 42% of connections and are at most 6 s apart in 99%. A message takes a median 28 s from Start MID to Message finished (10% under 13 s, 10% over 57 s), longer than on a real gateway, and longer at night (about 45 s) than by day (about 23 s).
  • Not covered: TLS, SMTP authentication, per-connection message reuse, delayed (soft-bounce) delivery, DLP, AMP, URL filtering, message filters, Subject with double quotes and log levels other than Info. SPF, DKIM and DMARC pass for legitimate inbound senders and are not logged for spam senders.

Sample Output

{
  "@timestamp": "2026-09-01T11:55:22.000Z",
  "cisco_secure_email_gateway": {
    "log": {
      "category": {
        "name": "mail_logs"
      },
      "host": "esa-01.contoso.example",
      "message": "MID 74652742 ready 9721387 bytes from \u003cf.sergeeva@contoso.example\u003e",
      "read_bytes": 9721387
    }
  },
  "ecs": {
    "version": "8.17.0"
  },
  "email": {
    "from": {
      "address": [
        "f.sergeeva@contoso.example"
      ]
    },
    "message_id": "74652742"
  },
  "event": {
    "dataset": "cisco_secure_email_gateway.log",
    "kind": "event",
    "original": "\u003c166\u003eSep  1 11:55:22 esa-01.contoso.example mail_logs: Info: MID 74652742 ready 9721387 bytes from \u003cf.sergeeva@contoso.example\u003e",
    "timezone": "UTC"
  },
  "log": {
    "level": "info",
    "syslog": {
      "priority": 166
    }
  },
  "tags": [
    "preserve_original_event"
  ]
}

Parameters

ParameterDefaultDescription
anomaly_modetrueAdd the recurring large-mail episode; false produces background only
anomaly_interval_hours24Hours from one episode start to the next due time, 1 to 8,760
host_nameesa-01.contoso.exampleGateway host name in the syslog header
interface_ip10.20.30.25Address of the Management interface
internal_domaincontoso.exampleDomain of internal users
relay_hosts[exch-01.contoso.example 10.20.10.11, exch-02.contoso.example 10.20.10.12]Internal Exchange hosts that relay outbound mail and receive inbound mail; users are assigned to them in turn
large_message_bytes8000000Size threshold of the episode messages; background never has three such messages to the sender's own mailbox within 40 minutes
max_message_bytes20000000Largest message the listener accepts
partner_domains8 domains (fabrikam.test ... wingtiptoys.test)Partner mail domains with their MX address and base reputation (SBRS)
freemail_domains[mail.example.com, webmail.example.net, inbox.example.org]Public mailbox providers; users' personal mailboxes are spread over them in turn
newsletter_senders[news@digest.example.com, noreply@events.example.net, offers@shop.example.org, updates@saas.example.com]Bulk senders marked as graymail

Related Generators