I tried the wiki and no luck
When I do the grep I get lots of data eg:
Feb 26 06:55:36 webmail postfix/smtpd[32320]: disconnect from cm81189.red.mundo-r.com[213.60.81.189]
Feb 26 06:55:36 webmail postfix/smtpd[725]: disconnect from unknown[74.72.52.20]
Feb 26 06:55:39 webmail postfix/smtpd[21673]: connect from blu139-omc1-s17.blu139.hotmail.com[65.55.175.157]
Feb 26 06:55:39 webmail postfix/smtpd[21673]: EB46118A1C31D: client=blu139-omc1-s17.blu139.hotmail.com[65.55.175.157]
Feb 26 06:55:40 webmail postfix/cleanup[27764]: EB46118A1C31D: message-id=<BLU113-W474159CE8572C12DD74345F3190@phx.gbl>
Feb 26 06:55:40 webmail postfix/qmgr[5561]: EB46118A1C31D: from=<nikkihlandry35437@hotmail.com>, size=1341, nrcpt=1 (queue active)
Feb 26 06:55:40 webmail postfix/smtpd[21673]: disconnect from blu139-omc1-s17.blu139.hotmail.com[65.55.175.157]
Feb 26 06:55:44 webmail postfix/smtpd[1373]: connect from localhost.localdomain[127.0.0.1]
Feb 26 06:55:44 webmail postfix/smtpd[1373]: F0E5A18A1C31E: client=localhost.localdomain[127.0.0.1]
Feb 26 06:55:44 webmail postfix/cleanup[734]: F0E5A18A1C31E: message-id=<BLU113-W474159CE8572C12DD74345F3190@phx.gbl>
Feb 26 06:55:44 webmail postfix/smtpd[1373]: disconnect from localhost.localdomain[127.0.0.1]
Feb 26 06:55:44 webmail postfix/qmgr[5561]: F0E5A18A1C31E: from=<nikkihlandry35437@hotmail.com>, size=1998, nrcpt=1 (queue active)
Feb 26 04:47:03 webmail amavis[24932]: (24932-18) Checking: vd9xyT8HanuM [85.100.93.229] <agilityn@conet-service.de> -> <multicast@networksensor.com>
Feb 26 04:47:07 webmail amavis[24932]: (24932-18) FWD via SMTP: <agilityn@conet-service.de> -> <multicast@networksensor.com>,BODY=7BIT 250 2.6.0 Ok, id=24932-18, from MTA([127.0.0.1]:10025): 250 2.0.0 Ok: queued as CDD2518A1C31D
Feb 26 04:47:07 webmail amavis[24932]: (24932-18) Passed SPAMMY, [85.100.93.229] [85.100.93.229] <agilityn@conet-service.de> -> <multicast@networksensor.com>, Message-ID: <867808336.62007653421649@conet-service.de>, mail_id: vd9xyT8HanuM, Hits: 8.331, size: 7226, queued_as: CDD2518A1C31D, 4466 ms
Feb 26 04:48:09 webmail amavis[14610]: (14610-07) ESMTP::10024 /opt/zimbra/amavisd/tmp/amavis-20080226T042258-14610: <cohosh1956@acottremovals.com.au> -> <multicast@networksensor.com> SIZE=1535 Received: from webmail.networksensor.com ([127.0.0.1]) by localhost (webmail.networksensor.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP for <multicast@networksensor.com>; Tue, 26 Feb 2008 04:48:09 -0800 (PST)
Yep zimbra.log is owned by zimbra. I think the only thing wrong is that the system doesn't have the hostname listed in the Logger DB for some reason for MTA. I've even done the logger reinitialize and still no luck... Only the Spam/AV and disk graphs show.
Thoughts?