Руководство Пользователя для Cisco Cisco Content Security Management Appliance M160

Скачать
Страница из 441
 
4-50
AsyncOS 8.1 for Cisco Content Security Management User Guide
Chapter 4      Using Centralized Email Security Reporting
  •
  •
Domain-Based Executive Summary Report
The Domain-Based Executive Summary report provides a synopsis of the incoming and outgoing 
message activity for one or more domains in your network. It is similar to the Executive Summary report, 
but it limits the report data to the messages sent to and from the domains that you specify. The outgoing 
mail summary shows data only when the domain in the PTR (pointer record) of the sending server 
matches a domain you specify. If multiple domains are specified, the appliance aggregates the data for 
all those domains into a single report. 
To generate reports for a subdomain, you must add its parent domain as a second-level domain in the 
reporting system of the Email Security appliance and the Security Management appliance. For example, 
if you add example.com as a second-level domain, its subdomains, such as subdomain.example.com, are 
available for reporting. To add second-level domains, use reportingconfig -> mailsetup -> tld
 
in the 
Email Security appliance CLI, and reportingconfig -> domain -> tld in the Security Management 
appliance CLI.
Unlike other scheduled reports, Domain-Based Executive Summary reports are not archived. 
Domain-Based Executive Summary Reports and Messages Blocked by Reputation Filtering 
Because messages blocked by reputation filtering do not enter the work queue, AsyncOS does not 
process these messages to determine the domain destination. An algorithm estimates the number of 
rejected messages per domain. To determine the exact number of blocked messages per domain, you can 
delay HAT rejections on the Security Management appliance until the messages reach the recipient level 
(RCPT TO). This allows AsyncOS to collect recipient data from the incoming messages. You can delay 
rejections using listenerconfig -> setup command on the Email Security appliance. However, this option 
can impact system performance. For more information about delayed HAT rejections, see the 
documentation for your Email Security appliance. 
Note
To see Stopped by Reputation Filtering results in your Domain-Based Executive Summary report on the 
Security Management appliance, you must have hat_reject_info enabled on both the Email Security 
appliance and the Security Management appliance.

To enable the hat_reject_info on the Security Management appliance, run the reportingconfig > 
domain > hat_reject_info
 command. 
Managing Lists of Domains and Recipients for Domain-Based Executive Summary Reports 
You can use a configuration file to manage the domains and recipients for a Domain-Based Executive 
Summary report. The configuration file is a text file that is stored in the configuration directory of the 
appliance. Each line in the file produces a separate report. This allows you to include a large number of 
domains and recipients in a single report, as well as define multiple domain reports in a single 
configuration file. 
Each line of the configuration file includes a space-separated list of domain names and a space-separated 
list of email addresses for the report recipients. A comma separates the list of domain names from the 
list of email addresses. You can include subdomains by appending the subdomain name and a period at 
the beginning of the parent domain name, such as subdomain.example.com. 
The following is a Single Report configuration file that generates three reports.