27.11.2012 Views

IronPort - daily management guide - AsyncOS 7.6.1

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 3 Tracking Email Messages<br />

Running a Search Query<br />

OL-25138-01<br />

Cisco <strong>IronPort</strong> <strong>AsyncOS</strong> 7.6 for Email Daily Management Guide<br />

Running a Search Query<br />

Message Event: Select the events to track. Options are “Virus Positive,” “Spam Positive,” “Suspect<br />

Spam,” “Delivered,” “Hard Bounced,” “Soft Bounced,” “Currently in Outbreak Quarantine,” “DLP<br />

Violations,” and “Quarantined as Spam.” Unlike most conditions that you add to a tracking query,<br />

events are added with an “OR” operator. Selecting multiple events expands the search.<br />

If you select “DLP Violations,” <strong>AsyncOS</strong> displays additional DLP-related options are displayed.<br />

Options are the DLP policy that the messages violated and the severity of the violation (“Critical,”<br />

“High,” “Medium,” and “Low”).<br />

By default, only administrators can view matched content when running searches for DLP<br />

violations. To allow other users, including delegated administrators, to view this content, enable the<br />

DLP Tracking Privileges through the System Administration > Users page. See Controllingling<br />

Access to Sensitive Information in Message Tracking, page 8-18 for more information.<br />

Message-ID Header and MID: Enter a text string for the “Message-ID:” header, the <strong>IronPort</strong><br />

message ID (MID), or both.<br />

Attachment Name: Select Begins With, Is, or Contains, and enter an ASCII or Unicode text string<br />

for one Attachment Name to find. Leading and trailing spaces are not stripped from the text you<br />

enter.<br />

To search for messages by running a query:<br />

Step 1 On the Monitor > Message Tracking page, complete the desired search fields.<br />

For more information about the available search fields, see Understanding Tracking Query Setup,<br />

page 3-3.<br />

You do not need to complete every field. Except for the Message Event options, the query is an<br />

“AND” search. The query returns messages that match the “AND” conditions specified in the search<br />

fields. For example, if you specify text strings for the envelope recipient and the subject line<br />

parameters, the query returns only messages that match both the specified envelope recipient and<br />

the subject line.<br />

Step 2 Click Search to submit the query. The query results are displayed at the bottom of the page. Each row<br />

corresponds to an email message.<br />

Figure 3-4 Message Tracking Query Results<br />

Step 3 If the number of returned rows is greater than the value specified in “Items per page” field, the results<br />

are displayed on multiple pages. To navigate through the pages, click the page numbers at the top or<br />

bottom of the list.<br />

3-5

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!