Cisco Cisco Content Security Management Appliance M680 Guía Para Resolver Problemas

Descargar
Página de 3
23. snmp_logs SNMP Logs Manual Download None 
24. sntpd_logs NTP logs Manual Download None 
25. status Status Logs Manual Download None 
26. system_logs System Logs Manual Download None 
27. trackerd_logs Tracking Logs Manual Download None 
28. updater_logs Updater Logs Manual Download None 
29. upgrade_logs Upgrade Logs Manual Download None 
Choose the operation you want to perform:
− NEW − Create a new log.
− EDIT − Modify a log subscription.
− DELETE − Remove a log subscription.
− SETUP − General settings.
− LOGHEADERS − Configure headers to log.
− HOSTKEYCONFIG − Configure SSH host keys.
[]> logheaders
Please enter the list of headers you wish to record in the 
log files.
Separate multiple headers with commas.
[]> X−IPAS−Result, X−IronPort−AV
Return to the main CLI prompt, and commit any/all changes.
When you review the mail_logs, you will see the outcome of the headers now injected into the logs as
configured:
Thu Aug 14 08:40:18 2014 Info: New SMTP ICID 10282 interface Management 
(192.168.0.199) address 192.168.0.200 reverse dns host ns.domain.com verified no
Thu Aug 14 08:40:18 2014 Info: ICID 10282 RELAY SG RELAY_SG match 192.168.0.200 
SBRS not enabled
Thu Aug 14 08:40:18 2014 Info: Start MID 1403 ICID 10282
Thu Aug 14 08:40:18 2014 Info: MID 1403 ICID 10282 From: <orig_user@domain.com>
Thu Aug 14 08:40:18 2014 Info: MID 1403 ICID 10282 RID 0 To: <end_user@example.com>
Thu Aug 14 08:40:18 2014 Info: MID 1403 using engine: SPF Verdict Cache using 
cached verdict
Thu Aug 14 08:40:18 2014 Info: SPF Verdict Cache cache status: hits = 7, misses = 12, 
expires = 0, adds = 12, seconds saved = 0.06, total seconds = 0.56
Thu Aug 14 08:40:18 2014 Info: MID 1403 SPF: helo identity postmaster@domain.com None 
Thu Aug 14 08:40:18 2014 Info: MID 1403 using engine: SPF Verdict Cache using 
cached verdict
Thu Aug 14 08:40:18 2014 Info: MID 1403 SPF: mailfrom identity orig_user@domain.com 
Pass (v=spf1) 
Thu Aug 14 08:40:18 2014 Info: MID 1403 using engine: SPF Verdict Cache using 
cached verdict
Thu Aug 14 08:40:18 2014 Info: MID 1403 SPF: pra identity orig_user@domain.com None 
headers from
Thu Aug 14 08:40:18 2014 Info: MID 1403 Message−ID '<20140814124103.GC6764@domain.com>'
Thu Aug 14 08:40:18 2014 Info: MID 1403 Subject 'Hello − this is the morning report...'
Thu Aug 14 08:40:18 2014 Info: MID 1403 ready 611 bytes from <orig_user@domain.com>
Thu Aug 14 08:40:18 2014 Info: MID 1403 matched all recipients for per−recipient policy 
DEFAULT in the outbound table
Thu Aug 14 08:40:18 2014 Info: ICID 10282 close
Thu Aug 14 08:40:20 2014 Info: MID 1403 interim verdict using engine: CASE spam negative
Thu Aug 14 08:40:20 2014 Info: MID 1403 using engine: CASE spam negative
Thu Aug 14 08:40:20 2014 Info: MID 1403 interim AV verdict using Sophos CLEAN
Thu Aug 14 08:40:20 2014 Info: MID 1403 antivirus negative 
Thu Aug 14 08:40:20 2014 Info: MID 1403 Outbreak Filters: verdict negative
Thu Aug 14 08:40:20 2014 Info: MID 1403 DLP no violation
Thu Aug 14 08:40:20 2014 Info: MID 1403 queued for delivery
Thu Aug 14 08:40:20 2014 Info: New SMTP DCID 173 interface 192.168.0.199 address 
111.22.111.22 port 25
Thu Aug 14 08:40:20 2014 Info: DCID 173 STARTTLS command not supported
Thu Aug 14 08:40:20 2014 Info: Delivery start DCID 173 MID 1403 to RID [0]