Mimecast Content Pack

The following content pack is available for use with a Graylog Illuminate license and Graylog Enterprise or Graylog Security. Contact sales to learn more about obtaining Illuminate.

Mimecast is a cloud-based cyber security provider specializing in email security and offering protection against phishing, malware, spam, and data leaks. It also delivers services for archiving, continuity, and threat intelligence to help organizations secure their communications and ensure compliance.

Supported Versions

  • Mimecast API 2.0

Requirements

  • Graylog 6.2.3+ with a valid Enterprise license

Stream Configuration

This technology pack includes 1 stream:

  • Illuminate:Mimecast Messages

Hint: If this stream does not exist prior to the activation of this pack then it will be created and configured to route messages to this stream and the associated index set. There should not be any stream rules configured for this stream.

Index Set Configuration

This technology pack includes 1 index set definition:

  • Mimecast Logs

Hint: If this index set is already defined, then nothing will be changed. If this index set does not exist, then it will be created with retention settings of a daily rotation and 90 days of retention. These settings can be adjusted as required after installation.

Log Collection

Mimecast utilizes the Mimecast input that ingests multiple Mimecast content types in JSON format. See the Graylog documentation for information on how to launch a new Mimecast input.

Configuration Example

Log Format Example

{"id":"eNoVzt0KgjAAQOF32e0EdWrNoIvZn6UGYZKKNzqHWaai2y4Wv","auditType":"User Logged On","user":"user@domain.com","eventTime":"2025-06-12T14:53:56+0000","eventInfo":"Successful authentication for user@domain.com <Domain User>, Date: 2025-06-12, Time: 16:53:56 SAST, IP: 192.168.100.100, Application: SMTP-MTA2, Method: Cloud","category":"authentication_logs"}

What is Provided

  • Rules to parse, normalize, and enrich Mimecast content pack messages.

  • A dashboard displaying events and statistics of interest.

  • Saved search highlighting key information using a user_email parameter.

Events Processed by This Technology Pack

The content pack supports the following log types. Generic processing will be provided for log types not listed.

GIM Categorization

GIM categorization is provided for the following messages:

Message Fields Included in This Pack

Fields of Note

Mimecast Spotlight Content Pack

This spotlight offers a dashboard with 2 tabs:

Overview

Saved Search