05.08.2013 Views

InterScanTM Messaging Security Virtual Appliance - Online Help ...

InterScanTM Messaging Security Virtual Appliance - Online Help ...

InterScanTM Messaging Security Virtual Appliance - Online Help ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Trend Micro InterScan <strong>Messaging</strong> <strong>Security</strong> <strong>Virtual</strong> <strong>Appliance</strong> Administrator’s Guide<br />

Querying Logs<br />

23-4<br />

You can perform queries on five types of events or information:<br />

• Message tracking: Records message details such as the sender, recipient(s),<br />

message size, and the final action that IMSVA or Cloud Pre-Filter has taken. The<br />

query result also indicates the name and type of the policy rule that was triggered.<br />

• System events: Tracks the time of system events such as user access, modification<br />

of rules, registration of MCP agent and so on.<br />

• Policy events: Provides details on the policy rules that were triggered, the actions<br />

taken, and the message details.<br />

• MTA events: Provides connection details of Postfix on the local computer where<br />

the central controller is installed.<br />

• IP filtering: Provides the time when IMSVA started and stopped blocking email<br />

messages from the queried IP address.<br />

Log Query Behavior<br />

With the inclusion of Cloud Pre-Filter to IMSVA, changes in the way that users can<br />

query logs have been introduced.<br />

Message Tracking Enhancement<br />

IMSVA splits Message tracking logs in to:<br />

• IMSVA data only: These message tracking logs only contain data from IMSVA.<br />

• Cloud Pre-Filter + IMSVA data: These message tracking logs contain data from<br />

the Cloud Pre-Filter and IMSVA.<br />

IMSVA includes hyperlinks for quarantined, archived, and postponed messages in<br />

Message tracking logs. This provides detailed information about those messages.<br />

Query Behavior<br />

IMSVA provides the following log query behavior:

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!