Analyze a raw message

Analyze a raw message with provided, active, or Feed rules in your Sublime organization. Raw messages are treated as inbound unless message_type specifies outbound or internal.

Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…
Body Params
message_type
object

Override on message types, defined from the perspective of your organization

queries
array of objects

Queries to analyze

queries
string
required

The full base64 encoded raw eml message

rules
array of objects

Rules to analyze

rules
boolean
Defaults to false

Whether to analyze the message with all active detection rules in your organization

boolean
Defaults to false

Whether to analyze the message with all active DLP rules in your organization. Requires read_dlp_rules, and the message being analyzed must be outbound or internal (sent).

boolean
Defaults to false

Whether to analyze with all detection rules from all Feeds, including uninstalled + inactive Feed rules, as well as any active detection rules you’ve created that are not part of a Feed.

boolean
Defaults to false

Whether to analyze with all DLP rules from all Feeds, including uninstalled + inactive Feed rules, as well as any active DLP rules you've created that are not part of a Feed. Requires read_dlp_rules, and the message being analyzed must be outbound or internal (sent).

boolean
Defaults to false

Whether to analyze with all insights

Response

Language
Credentials
Bearer
URL
LoadingLoading…
Response
Choose an example:
application/json