The following tables provide a full list of tokens that can be used in certain What To Do? actions and Policy References.
References to Web policy content are only available when a Web |
There are two types of token:
Token | Where Supported | Value |
---|---|---|
|
||
%ADMIN% |
Alert Annotation Inform Log entry Tag subject Add header |
The administrator account email address used by the Policy Engine when generating Informs. |
%ALARM_DESCRIPTION% |
Email Alarm Message |
A description of the raised alarm. |
%ALARM_TEXT% |
Email Alarm Message |
The text of the raised alarm. |
%ALARM_TYPE% |
Email Alarm Message |
The type of the raised alarm. |
%AREANAME% |
Alert Inform Log entry |
The name of the message area containing the message. |
%DATE% |
Alert Annotation Inform Log Message Tag subject Add header Notify Sender |
The date the original message was sent. |
%HOSTNAME% |
Email Alarm Message |
The hostname of the machine on which an alarm has been raised. |
%IPADDRESS% |
Email Alarm Message |
The IP address of the machine on which an alarm has been raised. |
%LOCALDATE% |
Alert Inform |
The date the original message was sent, shown in the |
%POLICY% |
Alert Annotation Inform Log entry Tag subject Add header |
A list of the content rules invoked on the message. |
%REMOVEDNAMES% |
Annotation Inform Tag subject Add header |
A list of the names of any removed attachments. |
%SENDER% |
Alert Annotation Inform Log entry Tag subject Add header |
The email address of the sender of the original message. |
%SERVER% |
Alert Annotation Inform Log entry Tag subject Add header |
The |
%SUBJECT% |
Alert Annotation Inform Log entry Tag subject Add header Notify Sender |
The subject of the original message. |
%UNIQUEID% |
Alert Annotation Inform Log entry Tag subject Add header |
The Mail ID: the unique ID |
|
||
%DETECTED% |
Alert Annotation Inform |
Items detected by the "What To Look For?" clauses in invoked content rules. |
%MANAGE_MESSAGE% |
Inform |
A manage message link that can be added to a Plain Format inform message. |
%MODIFIED% |
Annotation Inform |
Content rules that triggered, and hence modified the message. |
%POLICYVIOLATED% |
Notify Auditor |
The policy that was violated. |
%PRIMARYTHREATS% |
Alert Inform |
The threat type and name detected in a message. The values are separated by a colon, for example, VIRUS:EICAR. |
%RCPTS% |
Alert Annotation Inform Log entry Notify Sender |
A list of the recipients. (This is a concatenated list of all the "Recipient" responses). |
%RECOGNISED% |
Annotation Inform |
A list of the |
%RELEASEDBY% |
Notify Auditor |
The name of the person who released the message. |
%RESPONSES% |
Annotation Inform |
The values of all the above response tokens. |
Use tokens to configure the content of
Block Pages, Informs, and Email Alarm Messages by specifying values that
are only known at runtime. When the
Token | Where supported | Value |
---|---|---|
%ADMIN% |
Inform |
The |
%ALARM_DESCRIPTION% |
Email Alarm Message |
A description of the raised alarm. |
%ALARM_TEXT% |
Email Alarm Message |
The text of the raised alarm. |
%ALARM_TYPE% |
Email Alarm Message |
The type of the raised alarm. |
%CONTENTDETECTED% |
Block Page Inform |
The names of the triggered content rules. |
%DIAGNOSTICS% |
Block Page Inform |
A complete report of the data analysis. |
%FORMATTYPE% |
Block Page Inform |
The type of data recognized. |
%FORMATSUBTYPE% |
Block Page Inform |
The low level type of data recognized. |
%HOSTNAME% |
Email Alarm Message |
The hostname of the machine on which an alarm has been raised. |
%IPADDRESS% |
Email Alarm Message |
The IP address of the machine on which an alarm has been raised. |
%ROUTE% |
Block Page Inform |
The name of the route that determined the policy. |
%RULES% |
Block Page Inform |
A comma separated list of matched rules. |
%SERVERADDRESS% |
Inform |
The hostname of the |
%URL% |
Block Page Inform |
The full URL of the request. |
%URL_CATEGORY% |
Block Page Inform |
The URL category name for the current request. |
%USER% |
Block Page Inform |
The user name, or, if no user name is available, the IP address of the client machine. |
%USERADDRESS% |
Block Page Inform |
The IP address of the client machine. |
Token | Description |
---|---|
%DOC_OWNERS_COUNT% | The number of document owners where a match has been found. This token is available in both the subject and the body of a message. |
%DOC_SET_OWNERS% | The details of document owners of matched documents. |
%DOC_NAMES% | The file name and file location if available of registered documents where a match was found. |
%DOC_NAMES_CLASSIFICATION% | The file name and file location if available, and the classification of registered documents where a match was found. |
%DOC_NAMES_MATCH% |
The file name and file location if available, and the percentage match of registered documents where a match was found. |
%DOC_LIST_MATCHES% |
The file name and file location if available, and a list of matches for each registered document where a match was found. |
%DOC_NAMES_PROPERTIES% |
The file name and file location if available, and any custom properties for each registered document where a match was found. |
%DOC_SETS% | The collection name where matched registered documents were detected. . |
When informs are copied to the document owners, tokens will only show information relevant to documents registered for that particular document owner. |
Where supported | Meaning |
---|---|
Alert |
A Generate an Alert action in a Content Rule |
Annotation |
A Message Annotation Policy Reference |
Block Page |
A Block Page Policy Reference |
Email Alarm Message |
An email message that is sent to a specified address when an alarm is
raised, if the |
Inform |
An Inform Policy Reference |
Log entry |
A Log a Message action in a Content Rule |
Tag subject |
A Tag the Message Subject action in a Content Rule |
Add header |
An Add a Message Header action in a Content Rule |
Notify Sender |
An email message that is sent to a sender when a message is released, if the |
Notify Auditor |
An email message that is sent to an auditor when a message is released, if the |