The Email Event Activity widget provides information about threats that were detected in the email traffic that is protected by Symantec Email Security.cloud. These threats include links to malicious URLs and malicious file attachments.
The Email Event Activity widget requires that Synapse Symantec Email Security.cloud Correlation is enabled on your appliance. When enabled, Symantec Endpoint Detection and Response collects conviction events from Email Security.cloud. This widget displays the total number of events for a time period that you specify.
You can click through various parts of the Email Event Activity widget to view the information you want:
Click 7d, 1m, 3m, or All to view the information for the last 7 days, 1 month, 3 months, or all dates.
The line chart that appears represents the total number of conviction events detected during that time period. You can hover over the chart to display the total for an individual day within that period.
Click Malicious to display the total number of events that are identified as malicious.
This information is represented by a red area chart.
You can hover over this chart to display the total number of malicious events for each day within that time period. You can then click on the dot to navigate to the search results of the Email: Malicious quick filter. This filter displays information about the events that are included in the totals for the widget.
Click the following link to learn more about using the Events Summary view.