Messaging Gateway

 View Only
Expand all | Collapse all

Mail Gateway Message logs

SSE-JDavis

SSE-JDavisOct 30, 2009 11:02 AM

SSE-JDavis

SSE-JDavisOct 30, 2009 12:31 PM

Migration User

Migration UserOct 30, 2009 03:31 PM

  • 1.  Mail Gateway Message logs

    Posted Oct 28, 2009 03:25 PM
    I'm running a Symantec Brightmail Gateway version 8.0.2-12, and one thing that has annoyed me is the lack of a message log (or at least I can't find it). I'm used to the Barracudas, where you go to the "Message Log" and you get a list of every message that has come through the Barracuda, both inbound and outbound, and it allows you to mark messages that made it through as spam, whitelist messages that it thought where spam, etc. Is there a way to get a similar listing in the Brightmail Gateway, and if it's not already done (it doesn't appear to be), set it up so all messages that don't make it through are sent to the local quarantine, then deleted after however many days? I think the way mine is configured is very plain, out of the box, so messages that it thinks are spam are deleted, and other messages get forwarded on to my Exchange server.

    Thanks,
    Dave


  • 2.  RE: Mail Gateway Message logs

    Posted Oct 29, 2009 03:56 AM
    Hi,

    1) Message logs
    See "Message Audit Logs" for mails going trough Brightmail. Marking mails as you desribed is in the logs not possible and i do not know another way of doing this except for the spam quarantine to release mails.

    2) Spam quarantine
    Use "Spam > Policies > Email" and a default like "Spam or Suspected Spam: Quarantine message" or create your own. Then apply this setting to groups you created.
    Configure spam Quarantine: "Spam > Settings > Quarantine Settings > Spam Quarantine Expunger"


    Frank



  • 3.  RE: Mail Gateway Message logs

    Posted Oct 29, 2009 12:04 PM
    Thanks for the Tip; I modified my rules, and disabled all Spam policies except "Spam or Suspect Spam: Quarantine Message", and "Failed Bounce Attack Validation: Reject Message". Those are the only two applied to the "Default Group" (previously only the first two and "Failed Bounce Attack" where applied to a group). I also set all the "Bad Senders" rules to modify the subject line and hold in Quarantine. The odd thing is, since I made that change, the "Inbound E-Mail Message Summary" shows that zero spam has come in since I made the change, but when I go to "Message Audit Logs" and enter one of my e-mail addresses, it comes up with a bunch of messages, and the most recent four, about two hours ago, (among others) where blocked with a "Symantec Global Bad Sender" Verdict, and an action of "Modify the subject line, Hold message in Spam Quarantine" (This is what I set everything up to do). If I go to "Spam" > "Quarantine" > "E-Mail Spam", there's nothing there. Where did they go??

    As a rule, I like Symantec's Corporate products, but I really don't like the Brightmail Gateway. It's counter-intuitive, and the message logs suck. Why is there a "Mandatory Filter Value" in the "Message Audit Logs"?? Why can't there be a "Show ALL" option to see logs of ALL messages that have gone through the gateway, not just to or from a specific address? You should get an "ALL" view by default, with an option to filter.


  • 4.  RE: Mail Gateway Message logs

    Broadcom Employee
    Posted Oct 29, 2009 12:21 PM
    That can be accomplished by just putting a period in the search field and seting the mandatory filter to email address.

    I suspect that we don't have a defautl option to do this becuase we expected people to have a reason or specific item they are looking for instead of just taking a look at the most current items or such.


  • 5.  RE: Mail Gateway Message logs

    Posted Oct 29, 2009 12:31 PM
    Thanks TSE-JDAvis, That answers that question, but the question still remains: Where are the messages that where classified as spam or where from a sender with a bad reputation that where configured to be held in Quarantine, and are reported as such, but the Quarantine is reported as empty?


  • 6.  RE: Mail Gateway Message logs

    Broadcom Employee
    Posted Oct 29, 2009 01:04 PM
    They will be in the message audit logs if they came through the appliance. If they are not, they were not marked as spam by the appliance but possibly by another product.


  • 7.  RE: Mail Gateway Message logs

    Posted Oct 29, 2009 01:16 PM
    Messages are showing in the Audit Logs, but the messages that are shown as spam and should be delivered to Quarantine aren't in the Quarantine. There are no other products filtering spam. It goes Internet > Brightmail Gateway Virtual Appliance > Exchange Server.


  • 8.  RE: Mail Gateway Message logs

    Broadcom Employee
    Posted Oct 29, 2009 02:10 PM
    What does it list as the verdict and actions taken? Also, do you have a user quarantine set up or an administrator only quarantine?


  • 9.  RE: Mail Gateway Message logs

    Posted Oct 29, 2009 05:52 PM
    Administrator Only. The actions are "Modify the subject line, Hold message in Spam Quarantine" for the various "Bad Sender" rules and "Hold message in Spam Quarantine" for "Spam" and "Suspected Spam".

    Another thing that's come up since I started "playing" with the filter and trying to tweak it is I've started getting "Delivery Delayed" messages with my e-mail address as the delivery address. The body is below:

    Delivery is delayed to these recipients or distribution lists:
     
    Subject: [Symantec Bad Sender] Boss fined you
     
    This message has not yet been delivered. Microsoft Exchange will continue to try delivering the message on your behalf.


  • 10.  RE: Mail Gateway Message logs

    Broadcom Employee
    Posted Oct 29, 2009 05:59 PM
    Can you provide a screen shot of  the details of a message in the audit log where the message that was supposed to be quarantined but it is not in there? This behaviour is not consistent with how the appliance software works.


  • 11.  RE: Mail Gateway Message logs

    Posted Oct 29, 2009 08:21 PM
    Here is a shot of the relevant columns; Can't get the whole thing on my 12" screen.



  • 12.  RE: Mail Gateway Message logs

    Broadcom Employee
    Posted Oct 30, 2009 11:02 AM
    And what is currently in the spam quarantine?


  • 13.  RE: Mail Gateway Message logs

    Posted Oct 30, 2009 11:05 AM
    Absolutely nothing. It simply states "There are no messages"


  • 14.  RE: Mail Gateway Message logs

    Broadcom Employee
    Posted Oct 30, 2009 12:31 PM
    Can I see a screenshot?


  • 15.  RE: Mail Gateway Message logs

    Posted Oct 30, 2009 03:31 PM


  • 16.  RE: Mail Gateway Message logs

    Broadcom Employee
    Posted Oct 30, 2009 04:20 PM
    What settings do you have for the Spam Quarantine limits?


  • 17.  RE: Mail Gateway Message logs

    Posted Oct 30, 2009 04:53 PM
    None, really. no max message size, no max number of mesages, Messages are deleted from Quarentine after 60 days.


  • 18.  RE: Mail Gateway Message logs

    Broadcom Employee
    Posted Oct 30, 2009 05:07 PM
    At this point you might want to call is so someone can help you live, I am personally stumped as to why we say messages went to quarantine but they are not there, unless your hard drive has filled up in the past and your MySQL tables are broken.


  • 19.  RE: Mail Gateway Message logs

    Posted Oct 30, 2009 05:12 PM

    It's never filled up as far as I know, but maybe I'll rebuld it from scratch and see if it gets fixed.



  • 20.  RE: Mail Gateway Message logs

    Posted Nov 03, 2009 10:19 AM
    Is thre a firewall between the scanner and the CC with the Quarantine store?   Any blocked traffic between the scanner and CC?


  • 21.  RE: Mail Gateway Message logs

    Posted Nov 04, 2009 04:32 PM
    Hi,

    So, you gave part of the MAL screenshot above - if you click on the TO address for one of the records for a Quarantined email, you'll see a bunch more data.
    What does it say under Delivery?



    I just wonder if these messages are being held in the queue because they can't reach the Quarantine server.

    //ian