Symantec 10490452 Administration Guide - Page 184

Message tracking, Enable message tracking, Searching for a message

Page 184 highlights

184 Administering the system Getting status information Message tracking Symantec Mail Security for SMTP provides a message tracking component allowing you to search for messages and find out what has happened to them. When enabled, message tracking provides administrators of Symantec Mail Security for SMTP with a trail of detailed information about every message that has been accepted and processed by the software. Auditing information is used to track what decisions were made within a single scanner framework. Message tracking and its associated logs is not intended to replace debug or information level logging. Where message tracking is distinctly different from standard scanner logging is that logged information is specifically associated with a message. To use message tracking, employ the information and procedures described in the following sections. Enable message tracking By default, message tracking is disabled. You must enable this feature before any tracking information is available for viewing or searching. It is important to realize that logs for message tracking can become large, and searching the logs can create high demand for Scanner processing time. To enable message tracking 1 In the Control Center, click Settings > Logs. 2 Select the host on which to enable message tracking. 3 Under Message Tracking Logs, check Enable message logs. 4 Click Save. Searching for a message A query facility is provided to search the message tracking log to determine if one or more messages meet the criteria for the message you want to find. The Message Tracking logs page enables you to specify either one or two criteria and related supplementary information as follows: ■ Host-One or more Scanners running Symantec Mail Security for SMTP. In order to find all details about a message, search on all attached Scanners. ■ Time range-Period of time for the search to query the audit log. While it is possible to search for longer periods, it is recommended that message searches not exceed one week. ■ Mandatory filter-Required search criteria that can be any one of the following: ■ Sender-Name of the message sender

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258

184
Administering the system
Getting status information
Message tracking
Symantec Mail Security for SMTP provides a message tracking component
allowing you to search for messages and find out what has happened to them.
When enabled, message tracking provides administrators of Symantec Mail
Security for SMTP with a trail of detailed information about every message that
has been accepted and processed by the software. Auditing information is used
to track what decisions were made within a single scanner framework. Message
tracking and its associated logs is not intended to replace debug or information
level logging. Where message tracking is distinctly different from standard
scanner logging is that logged information is specifically associated with a
message.
To use message tracking, employ the information and procedures described in
the following sections.
Enable message tracking
By default, message tracking is disabled. You must enable this feature before
any tracking information is available for viewing or searching. It is important to
realize that logs for message tracking can become large, and searching the logs
can create high demand for Scanner processing time.
To enable message tracking
1
In the Control Center, click
Settings
>
Logs
.
2
Select the host on which to enable message tracking.
3
Under Message Tracking Logs, check
Enable message logs
.
4
Click
Save
.
Searching for a message
A query facility is provided to search the message tracking log to determine if
one or more messages meet the criteria for the message you want to find. The
Message Tracking logs page enables you to specify either one or two criteria and
related supplementary information as follows:
Host—One or more Scanners running Symantec Mail Security for SMTP. In
order to find all details about a message, search on all attached Scanners.
Time range—Period of time for the search to query the audit log. While it is
possible to search for longer periods, it is recommended that message
searches not exceed one week.
Mandatory filter—Required search criteria that can be any one of the
following:
Sender—Name of the message sender