# Missing md5 field in Harmony Email & Collaboration integration with Elastic

**URL:** <https://discuss.elastic.co/t/missing-md5-field-in-harmony-email-collaboration-integration-with-elastic/380401>\
**Category:** SIEM\
**Created:** [July 23, 2025, 10:52pm UTC](https://discuss.elastic.co/t/missing-md5-field-in-harmony-email-collaboration-integration-with-elastic/380401 "2025-07-23T22:52:49Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![jares](https://avatars.discourse-cdn.com/v4/letter/j/db5fbb/32.png) [@jares](https://discuss.elastic.co/u/jares)\
**Post date:** [July 23, 2025, 10:52pm UTC](https://discuss.elastic.co/t/missing-md5-field-in-harmony-email-collaboration-integration-with-elastic/380401/1 "2025-07-23T22:52:50Z")

</div>

We are currently using the [Checkpoint Harmony Email & Collaboration integration](https://www.elastic.co/docs/reference/integrations/checkpoint_email) to forward logs to our ELK stack. However, we have noticed that the `md5` field—which contains the hash values of email attachments—is missing in the parsed events within Elasticsearch, even though it is present in the original JSON payload received via Syslog.

This field is critical for threat detection and correlation in our SIEM dashboards, especially when analyzing DLP and malicious attachment events.

Could this be a parsing issue in the integration package? Or is it expected behavior due to ECS mapping constraints?

Any clarification or update to the integration would be highly appreciated.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [August 19, 2025, 12:06am UTC](https://discuss.elastic.co/t/missing-md5-field-in-harmony-email-collaboration-integration-with-elastic/380401/2 "2025-08-19T00:06:48Z")

</div>

Can you share sanitized copy of the `event.original` value from the checkpoint\_email integration where `md5` is present that can be used to improve the integration’s test? `event.original` will be saved in the events produced from the checkpoint API when [Preserve original event](https://github.com/elastic/integrations/blob/19a4c3833bcb9b4a5c8b803a33942f330880f7fb/packages/checkpoint_email/data_stream/event/manifest.yml#L54-L55) is toggled on in the integration’s settings.

I don’t see any samples containing md5 in the test data for the integration. So it may be that the field is not used by the pipeline right now.

> <https://github.com/elastic/integrations/blob/050f9ff9ff105434963df48194e8c40de8163a70/packages/checkpoint_email/data_stream/event/_dev/test/pipeline/test-event.log>

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 16, 2025, 12:06am UTC](https://discuss.elastic.co/t/missing-md5-field-in-harmony-email-collaboration-integration-with-elastic/380401/3 "2025-09-16T00:06:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
