---
title: "mail.mimecast"
canonical: "https://docs.devo.com/space/latest/94662225/mail.mimecast"
format: markdown
---
> Macro (toc)

## Introduction

The tags beginning with `mail.mimecast` identify events generated by [Mimecast](https://www.mimecast.com/).

## Valid tags and data tables

<span style="color: #282828">The full tag must have </span>4 <span style="color: #282828">levels. The first two are fixed as</span> `mail.mimecast`<span style="color: #282828">. The third level identifies the type of events sent, and the fourth level indicates the event subtype.</span>

These are the valid tags and corresponding data tables that will receive the parsers' data:

| **Data tables** | **Tags** | **Data tables** |
| --- | --- | --- |
| Mimecast Secure Email Gateway  
Mimecast Targeted Threat Protection | `mail.mimecast.account.dashboard` | `mail.mimecast.account.dashboard` |
| `mail.mimecast.archive` | `mail.mimecast.archive` |
| `mail.mimecast.archive.messageview` | `mail.mimecast.archive.messageview` |
| `mail.mimecast.archive.search` | `mail.mimecast.archive.search` |
| `mail.mimecast.audit.events` | `mail.mimecast.audit.events` |
| `mail.mimecast.message.list` | `mail.mimecast.message.list` |
| `mail.mimecast.message.summary` | `mail.mimecast.message.summary` |
| `mail.mimecast.siem` | `mail.mimecast.siem` |
| `mail.mimecast.siem.attachment_v2` | `mail.mimecast.siem.attachment_v2` |
| `mail.mimecast.siem.av` | `mail.mimecast.siem.av` |
| `mail.mimecast.siem.av_v2` | `mail.mimecast.siem.av_v2` |
| `mail.mimecast.siem.delivery` | `mail.mimecast.siem.delivery` |
| `mail.mimecast.siem.delivery_v2` | `mail.mimecast.siem.delivery_v2` |
| `mail.mimecast.siem.iep` | `mail.mimecast.siem.iep` |
| `mail.mimecast.siem.iep_v2` | `mail.mimecast.siem.iep_v2` |
| `mail.mimecast.siem.impersonation_v2` | `mail.mimecast.siem.impersonation_v2` |
| `mail.mimecast.siem.jrnl` | `mail.mimecast.siem.jrnl` |
| `mail.mimecast.siem.jrnl_v2` | `mail.mimecast.siem.jrnl_v2` |
| `mail.mimecast.siem.process` | `mail.mimecast.siem.process` |
| `mail.mimecast.siem.process_v2` | `mail.mimecast.siem.process_v2` |
| `mail.mimecast.siem.receipt` | `mail.mimecast.siem.receipt` |
| `mail.mimecast.siem.receipt_v2` | `mail.mimecast.siem.receipt_v2` |
| `mail.mimecast.siem.spameventthread` | `mail.mimecast.siem.spameventthread` |
| `mail.mimecast.siem.spam_v2` | `mail.mimecast.siem.spam_v2` |
| `mail.mimecast.siem.ttp` | `mail.mimecast.siem.ttp` |
| `mail.mimecast.siem.url_v2` | `mail.mimecast.siem.url_v2` |
| `mail.mimecast.threat.feed` | `mail.mimecast.threat.feed` |
| `mail.mimecast.ttp` | `mail.mimecast.ttp` |
| `mail.mimecast.ttp.attachment` | `mail.mimecast.ttp.attachment` |
| `mail.mimecast.ttp.attachment_protect` | `mail.mimecast.ttp.attachment_protect` |
| `mail.mimecast.ttp.impersonation` | `mail.mimecast.ttp.impersonation` |
| `mail.mimecast.ttp.impersonation` | `mail.mimecast.ttp.impersonation` |
| `mail.mimecast.ttp.url` | `mail.mimecast.ttp.url` |

## <span style="color: #282828">How is the data sent to Devo?</span>

Events may be sent directly to Devo using the Mimecast API or using our [Devo relay](https://devodocs.atlassian.net/wiki/spaces/latest/pages/96468993).

## Table structure

These are the fields displayed in these tables:

> Macro (rw-ui-tabs-macro)
> 
> > Macro (rw-tab)
> 
> - [mail.mimecast.account.dashboard](#tag1)
> - [mail.mimecast.archive](#tag2)
> - [mail.mimecast.archive.messageview](#tag3)
> - [mail.mimecast.archive.search](#tag4)
> - [mail.mimecast.audit.events](#tag5)
> - [mail.mimecast.message.list](#tag6)
> 
> ### > Macro (anchor)
> 
> mail.mimecast.account.dashboard
> 
> | **Field** | **Type** | ***Extra***** fields** |
> | --- | --- | --- |
> | *eventdate* | `timestamp` |  |
> | *hostname* | `str` |  |
> | *id* | `str` |  |
> | *customercode* | `str` |  |
> | *clustercode* | `str` |  |
> | *displaymessage* | `str` |  |
> | *noticetype* | `str` |  |
> | *warninglevel* | `str` |  |
> | *visiblefrom* | `str` |  |
> | *title* | `str` |  |
> | *enabled* | `bool` |  |
> | *hostchain* | `str` | **✓** |
> | *tag* | `str` | **✓** |
> | *rawMessage* | `str` | **✓** |
> 
> ### > Macro (anchor)
> 
> mail.mimecast.archive
> 
> | **Field** | **Type** | **Source field name** | ***Extra***** fields** |
> | --- | --- | --- | --- |
> | *eventdate* | `timestamp` |  |  |
> | *type* | `str` | *vtype* |  |
> | *message* | `str` | *rawMessage* |  |
> | *hostchain* | `str` |  | **✓** |
> | *tag* | `str` |  | **✓** |
> | *rawMessage* | `str` |  | **✓** |
> 
> ### > Macro (anchor)
> 
> mail.mimecast.archive.messageview 
> 
> | **Field** | **Type** | ***Extra***** fields** |
> | --- | --- | --- |
> | *eventdate* | `timestamp` |  |
> | *timestamp* | `timestamp` |  |
> | *from* | `str` |  |
> | *to* | `str` |  |
> | *viewer* | `str` |  |
> | *source* | `str` |  |
> | *contentViewed* | `bool` |  |
> | *discoveryCase* | `bool` |  |
> | *viewed* | `timestamp` |  |
> | *subject* | `str` |  |
> | *rawMessage* | `str` | **✓** |
> | *hostchain* | `str` | **✓** |
> | *tag* | `str` | **✓** |
> 
> ### > Macro (anchor)
> 
> mail.mimecast.archive.search
> 
> | **Field** | **Type** | **Field transformation** | **Source field name** | ***Extra***** fields** |
> | --- | --- | --- | --- | --- |
> | *eventdate* | `timestamp` |  |  |  |
> | *timestamp* | `timestamp` |  |  |  |
> | *status* | `str` |  |  |  |
> | *received* | `timestamp` |  |  |  |
> | *attachments* | `bool` |  |  |  |
> | *route* | `str` |  |  |  |
> | *fromEnv_displayableName* | `str` |  |  |  |
> | *fromEnv_emailAddress* | `str` |  |  |  |
> | *fromHdr_displayableName* | `str` |  |  |  |
> | *fromHdr_emailAddress* | `str` |  |  |  |
> | *to_displayableName_str* | `str` | ```
> join(to_displayableName, ", ")
> ``` | *to_displayableName* |  |
> | *to_emailAddress_str* | `str` | ```
> join(to_emailAddress, ", ")
> ``` | *to_emailAddress* |  |
> | *senderIP* | `ip4` |  |  |  |
> | *id* | `str` |  |  |  |
> | *subject* | `str` |  |  |  |
> | *rawMessage* | `str` |  |  | **✓** |
> | *hostchain* | `str` |  |  | **✓** |
> | *tag* | `str` |  |  | **✓** |
> 
> ### > Macro (anchor)
> 
> mail.mimecast.audit.events
> 
> | **Field** | **Type** | ***Extra***** fields** |
> | --- | --- | --- |
> | *eventdate* | `timestamp` |  |
> | *timestamp* | `timestamp` |  |
> | *id* | `str` |  |
> | *category* | `str` |  |
> | *auditType* | `str` |  |
> | *user* | `str` |  |
> | *eventInfo* | `str` |  |
> | *hostchain* | `str` | ** ✓** |
> | *tag* | `str` | **✓** |
> | *rawMessage* | `str` | **✓** |
> 
> ### > Macro (anchor)
> 
> mail.mimecast.message.list
> 
> | **Field** | **Type** | ***Extra***** fields** |
> | --- | --- | --- |
> | *eventdate* | `timestamp` |  |
> | *hostname* | `str` |  |
> | *reason* | `str` |  |
> | *reasonid* | `str` |  |
> | *reasoncode* | `str` |  |
> | *from2__emailaddress* | `str` |  |
> | *from2__displayablename* | `str` |  |
> | *fromheader__emailaddress* | `str` |  |
> | *fromheader__displayablename* | `str` |  |
> | *to__emailaddress* | `str` |  |
> | *to__displayablename* | `str` |  |
> | *subject* | `str` |  |
> | *route* | `str` |  |
> | *hasattachments* | `bool` |  |
> | *size* | `int4` |  |
> | *datereceived* | `str` |  |
> | *policyinfo* | `str` |  |
> | *hostchain* | `str` | ** ✓** |
> | *tag* | `str` | **✓** |
> | *rawMessage* | `str` | **✓** |
> 
> > Macro (rw-tab)
> 
> - [mail.mimecast.message.summary](#tag7)
> - [mail.mimecast.siem](#tag8)
> - [mail.mimecast.siem.av](#tag9)
> - [mail.mimecast.siem.delivery](#tag10)
> - [mail.mimecast.siem.iep](#tag11)
> - [mail.mimecast.ttp.impersonation](#tag12)
> 
> ### > Macro (anchor)
> 
> mail.mimecast.message.summary
> 
> | **Field** | **Type** | ***Extra***** fields** |
> | --- | --- | --- |
> | *eventdate* | `timestamp` |  |
> | *hostname* | `str` |  |
> | *policyinfo* | `str` |  |
> | *numberofitems* | `int4` |  |
> | *hostchain* | `str` | ** ✓** |
> | *tag* | `str` | **✓** |
> | *rawMessage* | `str` | **✓** |
> 
> ### > Macro (anchor)
> 
> mail.mimecast.siem
> 
> | **Field** | **Type** | **Source field name** | ***Extra***** fields** |
> | --- | --- | --- | --- |
> | *eventdate* | `timestamp` |  |  |
> | *type* | `str` | *vtype* |  |
> | *datetime* | `timestamp` |  |  |
> | *aCode* | `str` |  |  |
> | *acc* | `str` |  |  |
> | *ip* | `ip4` |  |  |
> | *dir* | `str` |  |  |
> | *msgId* | `str` |  |  |
> | *subject* | `str` |  |  |
> | *headerFrom* | `str` |  |  |
> | *sender* | `str` |  |  |
> | *rcpt* | `str` |  |  |
> | *act* | `str` |  |  |
> | *tlsVer* | `str` |  |  |
> | *cphr* | `str` |  |  |
> | *rejType* | `str` |  |  |
> | *rejCode* | `int4` |  |  |
> | *rejInfo* | `str` |  |  |
> | *error* | `str` |  |  |
> | *attCnt* | `int4` |  |  |
> | *attSize* | `int4` |  |  |
> | *route* | `str` |  |  |
> | *message* | `str` | *rawMessage* |  |
> | *rawMessage* | `str` |  | ** ✓** |
> | *hostchain* | `str` |  | **✓** |
> | *tag* | `str` |  | **✓** |
> 
> ### > Macro (anchor)
> 
> mail.mimecast.siem.av
> 
> | **Field** | **Type** | ***Extra***** fields** |
> | --- | --- | --- |
> | *eventdate* | `timestamp` |  |
> | *datetime* | `timestamp` |  |
> | *acc* | `str` |  |
> | *mimecastIP* | `bool` |  |
> | *fileName* | `str` |  |
> | *sha256* | `str` |  |
> | *size* | `int4` |  |
> | *ip* | `ip4` |  |
> | *recipient* | `str` |  |
> | *senderDomain* | `str` |  |
> | *fileExt* | `str` |  |
> | *subject* | `str` |  |
> | *msgId* | `str` |  |
> | *sender* | `str` |  |
> | *virus* | `str` |  |
> | *sha1* | `str` |  |
> | *senderDomainInternal* | `bool` |  |
> | *fileMime* | `str` |  |
> | *customerIP* | `bool` |  |
> | *route* | `str` |  |
> | *md5* | `str` |  |
> | *rawMessage* | `str` | ** ✓** |
> | *hostchain* | `str` | **✓** |
> | *tag* | `str` | **✓** |
> 
> ### > Macro (anchor)
> 
> mail.mimecast.siem.delivery
> 
> | **Field** | **Type** | ***Extra***** fields** |
> | --- | --- | --- |
> | *eventdate* | `timestamp` |  |
> | *datetime* | `timestamp` |  |
> | *aCode* | `str` |  |
> | *acc* | `str` |  |
> | *ip* | `ip4` |  |
> | *dir* | `str` |  |
> | *msgId* | `str` |  |
> | *subject* | `str` |  |
> | *sender* | `str` |  |
> | *rcpt* | `str` |  |
> | *tlsVer* | `str` |  |
> | *cphr* | `str` |  |
> | *rejType* | `str` |  |
> | *rejCode* | `int4` |  |
> | *rejInfo* | `str` |  |
> | *error* | `str` |  |
> | *attCnt* | `int4` |  |
> | *attSize* | `int4` |  |
> | *delivered* | `bool` |  |
> | *receiptAck* | `str` |  |
> | *latency* | `int8` |  |
> | *attempt* | `int4` |  |
> | *snt* | `int4` |  |
> | *useTls* | `str` |  |
> | *route* | `str` |  |
> | *rawMessage* | `str` | ** ✓** |
> | *hostchain* | `str` | **✓** |
> | *tag* | `str` | **✓** |
> 
> ### > Macro (anchor)
> 
> mail.mimecast.siem.iep
> 
> | **Field** | **Type** | ***Extra***** fields** |
> | --- | --- | --- |
> | *eventdate* | `timestamp` |  |
> | *datetime* | `timestamp` |  |
> | *aCode* | `str` |  |
> | *acc* | `str` |  |
> | *sender* | `str` |  |
> | *urlCategory* | `str` |  |
> | *scanResultInfo* | `str` |  |
> | *recipient* | `str` |  |
> | *msgId* | `str` |  |
> | *subject* | `str` |  |
> | *url* | `str` |  |
> | *route* | `str` |  |
> | *rawMessage* | `str` | ** ✓** |
> | *hostchain* | `str` | **✓** |
> | *tag* | `str` | **✓** |
> 
> ### > Macro (anchor)
> 
> mail.mimecast.ttp.impersonation
> 
> | **Field** | **Type** | **Field transformation** | **Source field name** | ***Extra***** fields** |
> | --- | --- | --- | --- | --- |
> | *eventdate* | `timestamp` |  | * * |  |
> | *timestamp* | `timestamp` |  | * * |  |
> | *id* | `str` |  | * * |  |
> | *senderAddress* | `str` |  | * * |  |
> | *recipientAddress* | `str` |  | * * |  |
> | *subject* | `str` |  | * * |  |
> | *definition* | `str` |  | * * |  |
> | *hits* | `int4` |  | * * |  |
> | *identifiers_str* | `str` | ```
> join(identifiers, ",")
> ``` | *identifiers* |  |
> | *action* | `str` |  | * * |  |
> | *taggedExternal* | `bool` |  | * * |  |
> | *taggedMalicious* | `bool` |  | * * |  |
> | *senderIpAddress* | `ip4` |  | * * |  |
> | *impersonationResults_impersonationDomainSource_str* | `str` | ```
> join(impersonationResults_impersonationDomainSource, ",")
> ``` | *impersonationResults_impersonationDomainSource* |  |
> | *impersonationResults_stringSimilarToDomain_str* | `str` | ```
> join(impersonationResults_stringSimilarToDomain, ",")
> ``` | *impersonationResults_stringSimilarToDomain* |  |
> | *impersonationResults_similarDomain_str* | `str` | ```
> join(impersonationResults_similarDomain, ",")
> ``` | *impersonationResults_similarDomain* |  |
> | *rawMessage* | `str` |  | * * | ** ✓** |
> | *hostchain* | `str` |  | * * | **✓** |
> | *tag* | `str` |  | * * | **✓** |
> 
> > Macro (rw-tab)
> 
> - [mail.mimecast.siem.jrnl](#tag13)
> - [mail.mimecast.siem.process](#tag14)
> - [mail.mimecast.siem.receipt](#tag15)
> - [mail.mimecast.siem.spameventthread](#tag16)
> - [mail.mimecast.siem.ttp](#tag17)
> - [mail.mimecast.threat.feed](#tag18)
> 
> ### > Macro (anchor)
> 
> mail.mimecast.siem.jrnl
> 
> | **Field** | **Type** | ***Extra***** fields** |
> | --- | --- | --- |
> | *eventdate* | `timestamp` |  |
> | *datetime* | `timestamp` |  |
> | *aCode* | `str` |  |
> | *acc* | `str` |  |
> | *dir* | `str` |  |
> | *sender* | `str` |  |
> | *rcpt* | `str` |  |
> | *rcptActType* | `str` |  |
> | *rcptHdrType* | `str` |  |
> | *rawMessage* | `str` | ** ✓** |
> | *hostchain* | `str` | **✓** |
> | *tag* | `str` | **✓** |
> 
> ### > Macro (anchor)
> 
> mail.mimecast.siem.process
> 
> | **Field** | **Type** | ***Extra***** fields** |
> | --- | --- | --- |
> | *eventdate* | `timestamp` |  |
> | *datetime* | `timestamp` |  |
> | *aCode* | `str` |  |
> | *acc* | `str` |  |
> | *msgId* | `str` |  |
> | *msgSize* | `int4` |  |
> | *act* | `str` |  |
> | *attCnt* | `int4` |  |
> | *attSize* | `int4` |  |
> | *attNames* | `str` |  |
> | *hld* | `str` |  |
> | *sender* | `str` |  |
> | *subject* | `str` |  |
> | *ipNewDomain* | `bool` |  |
> | *ipReplyMismatch* | `bool` |  |
> | *ipInternalName* | `bool` |  |
> | *ipThreadDict* | `bool` |  |
> | *ipSimilarDomain* | `bool` |  |
> | *rawMessage* | `str` | ** ✓** |
> | *hostchain* | `str` | **✓** |
> | *tag* | `str` | **✓** |
> 
> ### > Macro (anchor)
> 
> mail.mimecast.siem.receipt
> 
> | **Field** | **Type** | ***Extra***** fields** |
> | --- | --- | --- |
> | *eventdate* | `timestamp` |  |
> | *datetime* | `timestamp` |  |
> | *aCode* | `str` |  |
> | *acc* | `str` |  |
> | *ip* | `ip4` |  |
> | *dir* | `str` |  |
> | *msgId* | `str` |  |
> | *subject* | `str` |  |
> | *headerFrom* | `str` |  |
> | *sender* | `str` |  |
> | *rcpt* | `str` |  |
> | *act* | `str` |  |
> | *tlsVer* | `str` |  |
> | *cphr* | `str` |  |
> | *virus* | `str` |  |
> | *spamInfo* | `str` |  |
> | *spamLimit* | `int4` |  |
> | *spamScore* | `int4` |  |
> | *rejType* | `str` |  |
> | *rejCode* | `int4` |  |
> | *rejInfo* | `str` |  |
> | *error* | `str` |  |
> | *rawMessage* | `str` | ** ✓** |
> | *hostchain* | `str` | **✓** |
> | *tag* | `str` | **✓** |
> 
> ### > Macro (anchor)
> 
> mail.mimecast.siem.spameventthread
> 
> | **Field** | **Type** | ***Extra***** fields** |
> | --- | --- | --- |
> | *eventdate* | `timestamp` |  |
> | *hostname* | `str` |  |
> | *datetime* | `timestamp` |  |
> | *aCode* | `str` |  |
> | *acc* | `str` |  |
> | *Sender* | `str` |  |
> | *SourceIP* | `ip4` |  |
> | *Recipient* | `str` |  |
> | *SenderDomain* | `str` |  |
> | *Subject* | `str` |  |
> | *MsgId* | `str` |  |
> | *Route* | `str` |  |
> | *headerFrom* | `str` |  |
> | *hostchain* | `str` | ** ✓** |
> | *tag* | `str` | **✓** |
> | *rawMessage* | `str` | **✓** |
> 
> ### > Macro (anchor)
> 
> mail.mimecast.siem.ttp
> 
> | **Field** | **Type** | ***Extra***** fields** |
> | --- | --- | --- |
> | *eventdate* | `timestamp` |  |
> | *hostname* | `str` |  |
> | *datetime* | `timestamp` |  |
> | *acc* | `str` |  |
> | *reason* | `str` |  |
> | *subject* | `str` |  |
> | *msgid* | `str` |  |
> | *url* | `str` |  |
> | *route* | `str` |  |
> | *sourceIp* | `ip4` |  |
> | *sender* | `str` |  |
> | *recipient* | `str` |  |
> | *action* | `str` |  |
> | *urlCategory* | `str` |  |
> | *credentialTheft* | `str` |  |
> | *senderDomain* | `str` |  |
> | *hostchain* | `str` | ** ✓** |
> | *tag* | `str` | **✓** |
> | *rawMessage* | `str` | **✓** |
> 
> ### > Macro (anchor)
> 
> mail.mimecast.threat.feed
> 
> | **Field** | **Type** | ***Extra***** fields** |
> | --- | --- | --- |
> | *eventdate* | `timestamp` |  |
> | *hostname* | `str` |  |
> | *type* | `str` |  |
> | *id* | `str` |  |
> | *created* | `timestamp` |  |
> | *modified* | `timestamp` |  |
> | *name* | `str` |  |
> | *labels* | `str` |  |
> | *pattern* | `str` |  |
> | *valid_from* | `timestamp` |  |
> | *relationship_type* | `str` |  |
> | *source_ref* | `str` |  |
> | *target_ref* | `str` |  |
> | *hostchain* | `str` | ** ✓** |
> | *tag* | `str` | **✓** |
> | *rawMessage* | `str` | **✓** |
> 
> > Macro (rw-tab)
> 
> - [mail.mimecast.ttp](#tag19)
> - [mail.mimecast.ttp.attachment](#tag20)
> - [mail.mimecast.ttp.attachment_protect](#tag21)
> - [mail.mimecast.ttp.impersonation](#tag22)
> - [mail.mimecast.ttp.url](#tag23)
> 
> ### > Macro (anchor)
> 
> mail.mimecast.ttp
> 
> | **Field** | **Type** | **Source field name** | ***Extra***** fields** |
> | --- | --- | --- | --- |
> | *eventdate* | `timestamp` |  |  |
> | *type* | `str` | *vtype* |  |
> | *timestamp* | `timestamp` | * * |  |
> | *senderAddress* | `str` | * * |  |
> | *recipientAddress* | `str` | * * |  |
> | *action* | `str` | * * |  |
> | *route* | `str` | * * |  |
> | *result* | `str` | * * |  |
> | *actionTriggered* | `str` | * * |  |
> | *category* | `str` | * * |  |
> | *scanResult* | `str` | * * |  |
> | *message* | `str` | *rawMessage* |  |
> | *rawMessage* | `str` |  | ** ✓** |
> | *hostchain* | `str` |  | **✓** |
> | *tag* | `str` |  | **✓** |
> 
> ### > Macro (anchor)
> 
> mail.mimecast.ttp.attachment
> 
> | **Field** | **Type** | ***Extra***** fields** |
> | --- | --- | --- |
> | *eventdate* | `timestamp` |  |
> | *timestamp* | `timestamp` |  |
> | *senderAddress* | `str` |  |
> | *recipientAddress* | `str` |  |
> | *fileName* | `str` |  |
> | *fileType* | `str` |  |
> | *result* | `str` |  |
> | *actionTriggered* | `str` |  |
> | *details* | `str` |  |
> | *route* | `str` |  |
> | *rawMessage* | `str` | ** ✓** |
> | *hostchain* | `str` | **✓** |
> | *tag* | `str` | **✓** |
> 
> ### > Macro (anchor)
> 
> mail.mimecast.ttp.attachment_protect
> 
> | **Field** | **Type** | ***Extra***** fields** |
> | --- | --- | --- |
> | *eventdate* | `timestamp` |  |
> | *hostname* | `str` |  |
> | *datetime* | `str` |  |
> | *acc* | `str` |  |
> | *fileName* | `str` |  |
> | *sha256* | `str` |  |
> | *size* | `str` |  |
> | *iP* | `str` |  |
> | *recipient* | `str` |  |
> | *senderDomain* | `str` |  |
> | *fileExt* | `str` |  |
> | *msgId* | `str` |  |
> | *subject* | `str` |  |
> | *sender* | `str` |  |
> | *sha1* | `str` |  |
> | *fileMime* | `str` |  |
> | *route* | `str` |  |
> | *md5* | `str` |  |
> | *hostchain* | `str` | ** ✓** |
> | *tag* | `str` | **✓** |
> | *rawMessage* | `str` | **✓** |
> 
> ### > Macro (anchor)
> 
> mail.mimecast.ttp.impersonation
> 
> | **Field** | **Type** | **Field transformation** | **Source field name** | ***Extra***** fields** |
> | --- | --- | --- | --- | --- |
> | *eventdate* | `timestamp` |  |  |  |
> | *timestamp* | `timestamp` |  |  |  |
> | *id* | `str` |  |  |  |
> | *senderAddress* | `str` |  |  |  |
> | *recipientAddress* | `str` |  |  |  |
> | *subject* | `str` |  |  |  |
> | *definition* | `str` |  |  |  |
> | *hits* | `int4` |  |  |  |
> | *identifiers_str* | `str` | ```
> join(identifiers, ",")
> ``` | *identifiers* |  |
> | *action* | `str` |  | * * |  |
> | *taggedExternal* | `bool` |  | * * |  |
> | *taggedMalicious* | `bool` |  | * * |  |
> | *senderIpAddress* | `ip4` |  | * * |  |
> | *impersonationResults_impersonationDomainSource_str* | `str` | ```
> join(impersonationResults_impersonationDomainSource, ",")
> ``` | *impersonationResults_impersonationDomainSource* |  |
> | *impersonationResults_stringSimilarToDomain_str* | `str` | ```
> join(impersonationResults_stringSimilarToDomain, ",")
> ``` | *impersonationResults_stringSimilarToDomain* |  |
> | *impersonationResults_similarDomain_str* | `str` | ```
> join(impersonationResults_similarDomain, ",")
> ``` | *impersonationResults_similarDomain* |  |
> | *rawMessage* | `str` |  |  |  |
> | *hostchain* | `str` |  |  |  |
> | *tag* | `str` |  |  |  |
> 
> ### > Macro (anchor)
> 
> mail.mimecast.ttp.url
> 
> | **Field** | **Type** | ***Extra***** fields** |
> | --- | --- | --- |
> | *eventdate* | `timestamp` |  |
> | *timestamp* | `timestamp` |  |
> | *userEmailAddress* | `str` |  |
> | *url* | `str` |  |
> | *ttpDefinition* | `str` |  |
> | *action* | `str` |  |
> | *adminOverride* | `str` |  |
> | *userOverride* | `str` |  |
> | *scanResult* | `str` |  |
> | *category* | `str` |  |
> | *userAwarenessAction* | `str` |  |
> | *route* | `str` |  |
> | *rawMessage* | `str` | **✓** |
> | *hostchain* | `str` | **✓** |
> | *tag* | `str` | **✓** |