Skip to content

Commit 2e65bdd

Browse files
authored
Update threat-explorer-real-time-detections-about.md
1 parent 683dfed commit 2e65bdd

File tree

1 file changed

+8
-2
lines changed

1 file changed

+8
-2
lines changed

defender-office-365/threat-explorer-real-time-detections-about.md

Lines changed: 8 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -232,19 +232,25 @@ The filterable properties that are available in the **Delivery action** box in t
232232
|Composite|Select one or more values: <ul><li>**Fail**</li><li>**None**</li><li>**Pass**</li><li>**Soft pass**</li></ul>|
233233

234234
> [!TIP]
235-
> ¹ **Latest delivery location** doesn't include end-user actions on messages. For example, if the user deleted the message or moved the message to an archive or PST file.
235+
> **Latest delivery location** doesn't include end-user actions on messages. For example, if the user deleted the message or moved the message to an archive or PST file.
236236
>
237237
> There are scenarios where **Original delivery location**/**Latest delivery location** and/or **Delivery action** have the value **Unknown**. For example:
238238
>
239239
> - The message was delivered (**Delivery action** is **Delivered**), but an Inbox rule moved the message to a default folder other than the Inbox or Junk Email folder (for example, the Draft or Archive folder).
240240
> - ZAP attempted to move the message after delivery, but the message wasn't found (for example, the user moved or deleted the message).
241241
>
242-
> ² By default, a URL search maps to `http`, unless another value is explicitly specified. For example:
242+
> By default, a URL search maps to `http`, unless another value is explicitly specified. For example:
243243
>
244244
> - Searching with and without the `http://` prefix in **URL**, **URL Domain**, and **URL Domain and Path** should show the same results.
245245
> - Search for the `https://` prefix in **URL**. When no value is specified, the `http://` prefix is assumed.
246246
> - `/` at the beginning and end of the **URL path**, **URL Domain**, **URL domain and path** fields is ignored.
247247
> - `/` at the end of the **URL** field is ignored.
248+
>
249+
> **Sender IP** values are sometimes logged as empty or 0.0.0.0 for the following cases but the IP address might be visible in Exchange Message Trace:
250+
>
251+
> - Automatic replies
252+
> - Undelivered emails where delivery has failed
253+
> - Emails where sender IP is Microsoft internal IP (such as system generated notifications or alerts, forwarded messages delivered from Microsoft IP etc.)
248254
249255
### Pivots for the chart in the All email view in Threat Explorer
250256

0 commit comments

Comments
 (0)