Hello Atullo So, here one example: 1,2021/08/26 15:03:56,013201006616,THREAT,wildfire,2305,2021/08/26 15:03:51,1.1.1.1,2.2.2.2,0.0.0.0,0.0.0.0,SMTP-Traffic,,,smtp-base,vsys0,DMZ,EXT,ae2.2,ae1.1,PANORAMA,2021/08/26 15:03:51,1015351,1,58020,25,0,0,0x1102000,tcp,allow,"http://<url>/r/?id=tc08d19,8cb4a0,9b03889&p1=%40kjsI",Email Link(52143),phishing,high,client-to-server,6951421833034849569,0xa000000000000000,<countr>,10.0.0.0-10.255.255.255,0,,0,<sha256>,eu.wildfire.paloaltonetworks.com,0,,email-link,,,<sender-Email>,"Buy It, Mike!",<recipient Email>,5131320962,2060,1816,0,0,DMZ-1,<machinename>,,,,,0,,0,,N/A,unknown,WildFire-0,0x0,0,4294967295,,,<code>,0, I've replaced some stuff with <> and modified IP's, vlans etc. regards roger
... View more