Read Permitted Malicious Clicks

Fetch events for clicks to malicious URLs permitted in the specified time period.

The events returned for a specified range are based on the time that the event was created, not the time that the event occurred. The time an event is created is the later time of the following:

  • the time that the click occurred

  • the time that the threat referenced by click was recognized by Proofpoint

The input fields in this card are dynamically generated based on your instance.

Required fields are indicated in red.

Unless otherwise mentioned, all fields are text.


  • Range Type (dropdown): choose from available ranges



  • Interval (date): time interval to query in ISO 8601 format. The minimum interval allowed is 30 seconds and the maximum interval is 1 hour.

  • Since Time (date): start time of query in ISO 8601 format. The end of the period is the current API server time rounded to the nearest minute.

  • Since Seconds Ago (number): set start time of query to this many seconds before the current API server time (rounded to the nearest minute)


  • Query End Time (date): time the period being queried ended

  • Links (list)

    • URL: malicious URL that was clicked

    • Classification: threat category of the URL

    • Click Time (datetime): time at which the user clicked the URL

    • Threat Time (datetime): time at which Proofpoint identified the URL as a threat

    • User Agent: User-Agent header from the clicker's http request

    • Campaign ID: ID of campaign the threat belongs to, if available

    • Click IP: external IP address of user who clicked the URL

    • Sender: email address of sender; user-part is hashed and domain-part in plaintext

    • Recipient: email addresses of the recipient

    • Sender IP: IP address of the sender

    • ID: UUID of the event

    • GUID: unique Proofpoint Protection Server (PPS) identifier

    • Threat ID: unique identifier of the threat

    • Threat URL: link to threat entry on TAP dashboard

    • Threat Status: status of the threat

    • Message ID: message ID