Understanding message personalization options

While creating and updating notifications, you can insert (Message Personalization) variables to the body of the notifications.

Personalization Tag Description Access Session API
Application App user was trying to login to X X X
Condition
Comma separated text for the following conditions in rule that matched:
  • Consecutive Login Failures - "<N> login failures."
  • <N> will be replaced with number of failures that triggered match
  • Simultaneous Login Distance - "Simultaneous logins from geographically distant locations (<N> miles in <M> minutes)."
  • <N> will be replaced with number of miles between associated log events
  • <M> will be replaced with number of minutes between associated log events
  • New User-Agent+Location Detected - "Login detected from new device."
X
Device Match The Device type that matched the policy line X
Direction The direction of traffic flow when watermark was applied (Uploaded or Downloaded) X
Email Address User account Company Email attribute X X X
First Name User account First Name attribute X X X
IP Address Users IP address when watermark event occurred X X
Last Name User account Last Name attribute X X X
Location Associated log location (reverse IP or browser lookup) X X
Logout All Sessions Link A link that allows the user to logout all of their sessions across all devices. X X X
OS OS extracted from associated log User Agent X X
Password Change Link Link to allow the user to change their password (if Forcepoint ONE SSE is the IdP). X X X
Pattern_Name The name of the DLP pattern that was matched on the policy X
RDNS of IP Address Reverse-DNS of to find domain associated with IP X X
Region Match The region/location of the user at time of matching the policy line X X
Timestamp Watermark event timestamp in YYYY-MM-DD HH:MM GMT format X X X
Transaction ID Watermark event transaction ID X X