Cisco Cisco Email Security Appliance C190 Guia Do Utilizador

Página de 1211
 
38-9
AsyncOS 9.1.2 for Cisco Email Security Appliances User Guide
 
Chapter 38      Logging
  Log Types
Anti-Virus log
LDAP log
System log
Mail log
Using Text Mail Logs
They contain details of email receiving, email delivery and bounces. Status information is also written 
to the mail log every minute. These logs are a useful source of information to understand delivery of 
specific messages and to analyze system performance.
These logs do not require any special configuration. However, you must configure the system properly 
to view attachment names, and attachment names may not always be logged. For information, see 
 and 
Information displayed in text mail logs is shown in 
Interpreting a Text Mail Log
Use the following sample as a guide to interpret log files.
Note
Individual lines in log files are NOT numbered. They are numbered here only for sample purposes.
Table 38-4
Text Mail Log Statistics 
Statistic
Description
ICID
Injection Connection ID. This is a numerical identifier for an individual SMTP 
connection to the system, over which 1 to thousands of individual messages may 
be sent.
DCID
Delivery Connection ID. This is a numerical identifier for an individual SMTP 
connection to another server, for delivery of 1 to thousands of messages, each 
with some or all of their RIDs being delivered in a single message transmission.
RCID
RPC Connection ID. This is a numerical identifier for an individual RPC 
connection to the Spam quarantine. It is used to track messages as they are sent 
to and from the Spam Quarantine.
MID
Message ID: Use this to track messages as they flow through the logs.
RID
Recipient ID: Each message recipient is assigned an ID.
New
New connection initiated.
Start
New message started.
Table 38-5
Text Mail Log Detail 
1
Mon Apr 17 19:56:22 2003 Info: New SMTP ICID 5 interface Management (10.1.1.1) 
address 10.1.1.209 reverse dns host remotehost.com verified yes
2
Mon Apr 17 19:57:20 2003 Info: Start MID 6 ICID 5
3
Mon Apr 17 19:57:20 2003 Info: MID 6 ICID 5 From: <sender@remotehost.com>
4
Mon Apr 17 19:58:06 2003 Info: MID 6 ICID 5 RID 0 To: <mary@yourdomain.com>