Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 12-17-2010, 11:35 AM
Active Member
 
Posts: 36
Default Is there a quick way to determine the source of a message?

Going through our zimbra.log today and looking for potential problems, I noticed a number of messages being queued up for unreachable servers in places where I doubt we have any legitimate business activity. Using grep, I can see all of the resend attempts and disconnection by hex characters, or by the questionable domains. What I would LIKE to be able to figure out is how to trace which machine might possibly be sending messages, preferably by internal IP address. Is it necessary to install additional logging tools? Any ideas?
Reply With Quote
  #2 (permalink)  
Old 12-18-2010, 12:52 AM
Moderator
 
Posts: 1,432
Default

Usually you can search by messageID or other details, to locate the original injection of the message. However, if the messages have been sitting in the queue for a while, you might have to look at older logs, or the logs may even have been rotated out of existence. You might find some older info in /var/log/maillog or in /opt/zimbra/log/mailbox.log.

Also if you can locate the actual message (not sure where it's stored, shouldn't be hard to find, though), you can read the Received: headers assuming it was injected via SMTP. If it was injected via ZCO or ZWC, it *may* have have an X-Originating-IP header, provided you don't haven't turned it off in the Admin console.
__________________
Elliot Wilen
Berkeley, CA

Don't forget to enter your Zimbra version in your forum profile.
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.