27.11.2012 Views

IronPort - daily management guide - AsyncOS 7.6.1

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

OL-25138-01<br />

Tracking Email Messages<br />

This chapter contains the following sections:<br />

Tracking Service Overview, page 3-1<br />

Enabling and Disabling Local Message Tracking, page 3-2<br />

Understanding Tracking Query Setup, page 3-3<br />

Running a Search Query, page 3-5<br />

Understanding Tracking Query Results, page 3-6<br />

Tracking Service Overview<br />

CHAPTER<br />

3<br />

The message tracking service makes it easy to find the status of messages processed by <strong>AsyncOS</strong>, and<br />

you can quickly resolve help desk calls by determining the exact location of a message. You can use<br />

message tracking to determine if a particular message was delivered, found to contain a virus, or placed<br />

in a spam quarantine — or if it is located somewhere else in the mail stream.<br />

You can enable message tracking on your local Cisco <strong>IronPort</strong> Email Security appliance, or you can<br />

enable centralized tracking on an M-Series appliance to track messages for multiple email security<br />

appliances. For instructions on enabling centralized tracking, see the Cisco <strong>IronPort</strong> <strong>AsyncOS</strong> for<br />

Security Management User Guide . For instructions for enabling local tracking, see Enabling and<br />

Disabling Local Message Tracking, page 3-2.<br />

Instead of having to search through log files using “grep” or similar tools, you can use the flexible<br />

tracking interface to locate messages. You can use a variety of search parameters in combination.<br />

Tracking queries can include:<br />

Envelope information: Find messages from particular envelope senders or recipients by entering<br />

the text strings to match.<br />

Subject header: Match a text string in the subject line. Warning: Do not use this type of search in<br />

environments where regulations prohibit such tracking.<br />

Time frame: Find a message that was sent between specified dates and times.<br />

Sender IP address or rejected connections: Search for messages from a particular IP address, or<br />

show rejected connections in the search results.<br />

Event Information: Find messages that match specified events, such as messages flagged as virus<br />

positive, spam positive, or suspected spam, and messages that were delivered, hard bounced, soft<br />

bounced, or sent to the Virus Outbreak Quarantine.<br />

Cisco <strong>IronPort</strong> <strong>AsyncOS</strong> 7.6 for Email Daily Management Guide<br />

3-1

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!