27.11.2012 Views

IronPort - daily management guide - AsyncOS 7.6.1

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 5 Logging<br />

Domain Debug Log Example<br />

Using <strong>IronPort</strong> Injection Debug Logs<br />

OL-25138-01<br />

Sat Dec 21 02:37:22 2003 Info: 102503993 Sent: 'MAIL FROM:'<br />

Sat Dec 21 02:37:23 2003 Info: 102503993 Rcvd: '250 OK'<br />

Sat Dec 21 02:37:23 2003 Info: 102503993 Sent: 'RCPT TO:'<br />

Sat Dec 21 02:37:23 2003 Info: 102503993 Rcvd: '250 OK'<br />

Sat Dec 21 02:37:23 2003 Info: 102503993 Sent: 'DATA'<br />

Cisco <strong>IronPort</strong> <strong>AsyncOS</strong> 7.6 for Email Daily Management Guide<br />

Log Types<br />

Sat Dec 21 02:37:24 2003 Info: 102503993 Rcvd: '354 START MAIL INPUT, END WITH "." ON A<br />

LINE BY ITSELF'<br />

Sat Dec 21 02:37:24 2003 Info: 102503993 Rcvd: '250 OK'<br />

Injection debug logs record the SMTP conversation between the Cisco <strong>IronPort</strong> appliance and a specified<br />

host connecting to the system. Injection debug logs are useful for troubleshooting communication<br />

problems between the Cisco <strong>IronPort</strong> appliance and a client initiating a connection from the Internet.<br />

The log records all bytes transmitted between the two systems and classifies them as “Sent to” the<br />

connecting host or “Received from” the connecting host.<br />

You must designate the host conversations to record by specifying an IP address, an IP range, hostname,<br />

or partial hostname. Any connecting IP address within an IP range will be recorded. Any host within a<br />

partial domain will be recorded. The system performs reverse DNS lookups on connecting IP addresses<br />

to convert to hostnames. IP addresses without a corresponding PTR record in DNS will not match<br />

hostnames.<br />

You must also specify the number of sessions to record.<br />

Each line within an Injection Debug log contains the following information in Table 5-15.<br />

Table 5-15 Injection Debug Log Statistics<br />

Statistic Description<br />

Timestamp Time that the bytes were transmitted<br />

ICID The Injection Connection ID is a unique identifier that can be tied to the same<br />

connection in other log subscriptions<br />

Sent/Received Lines marked with “Sent to” are the actual bytes sent to the connecting host. Lines<br />

marked with “Received from” are the actual bytes received from the connecting<br />

host<br />

IP Address IP address of the connecting host<br />

5-23

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!