logs_query_help

Querying Logs

You can perform queries on five types of events or information:

Log Query Behavior

With the inclusion of Cloud Pre-Filter to IMSVA, changes in the way that users can query logs have been introduced.

IMSVA splits Message tracking logs in to:

IMSVA includes hyperlinks for quarantined, archived, and postponed messages in Message tracking logs. This provides detailed information about those messages.

IMSVA provides the following log query behavior:

General Query Information

Query

IMSVA Only

IMSVA + Cloud Pre-Filter

a@a.com

Only the exact match is returned.

Result: a@a.com

Displays all messages sent to any variant of "a@a.com", including those with multiple recipients.

Result:

  • za@a.com

  • a@a.com.us

  • a@a.com; b@a.com

  • b@a.com; a@a.com

  • b@a.com; a@a.com; c@a.com

Query conditions for Message track­ing left blank

  • Subject

  • Message ID

  • Sender

  • Recipient

All query conditions can be left blank

User must provide filtering cri­teria for at least one of the four query conditions.

* in Subject field

All other query con­ditions left blank

Returns all messages

Returns approximately 10000 query results

* in Message ID field

All other query con­ditions left blank

Returns all messages

Returns approximately 10000 query results

"Sender" Query Information

Query

IMSVA Only

IMSVA + Cloud Pre-Filter

5!#?

Valid Sender value in IMSVA, though no results will be returned.

Not supported.

User must provide a properly formatted, complete or partial email address.

*test@example.com

Valid Sender value in IMSVA.

Returns:

All variations ending with test@example.com

Not supported. The wildcard "*" is not supported in the Sender field.

test@example.com

Valid Sender value in IMSVA.

Returns:

Only messages sent from test@example.com

Valid Sender value in IMSVA.

Returns:

Only messages sent from test@example.com

"Recipient" Query Information

Query

IMSVA Only

IMSVA + Cloud Pre-Filter

test@example.com

Valid Recipient value in IMSVA.

Returns:

Only messages sent to test@example.com

Valid Recipient value in IMSVA.

Returns:

Approximately 10000 results sent to all variations of test@example.com (the same as using "*test@exam­ple.com*" in IMSVA Only data)

*test@example.com

Valid Recipient value in IMSVA.

Returns:

All variations ending with test@example.com

Not supported. The wildcard "*" is not supported in the Recipient field.

 

test@example.com*

Valid Recipient value in IMSVA.

Returns:

All variations starting with "test@example.com"

Not supported. The wildcard "*" is not supported in the Recipient field.

*test@example.com*

Valid Recipient value in IMSVA.

Returns:

All variations of test@example.com

Not supported. The wildcard "*" is not supported in the Recipient field.

  • Use test@example.com instead.

test@example.com; test2@example.com

Valid Recipient value in IMSVA.

Result:

Combined result of query­ing test@example.com and test2@example.com.

Not supported

  • Use "test@example.com" or "test2@example.com"

%^$&^

Valid Recipient value in IMSVA, though no results will be returned.

Not supported.

User must provide a properly formatted, complete or partial email address.

  1. Choose Logs > Query from the menu. The Log Query screen appears.

  2. Next to Type, select Message tracking. The query screen for message event logs appears.

  3. In the second drop-down box next to Type, select one of the following:

  4. Next to Dates, select a date and time range.

  5. Type any of the following additional information:

  6. Click Display Log. A timestamp, sender, recipient, subject, and last known action appear for each event.

  7. Click the timestamp link to see the following information:

  8. Perform any of the additional actions:

  1. Choose Logs > Query from the menu.

  2. Next to Type, select System events. The query screen for system event logs appears.

  3. In the second drop-down box next to Type, select one of the following:

  4. In the third drop-down box next to Type, select the server to view.

  5. Next to Dates, select a date and time range.

  6. Next to Description, type any special words to search for.

  7. Click Display Log. A timestamp, component, and description appear for each event.

  8. Perform any of the additional actions:

  1. Choose Logs > Query from the menu.

  2. Next to Type, select Policy events. The query screen for policy event logs appears.

  3. In the second drop-down box next to Type, select one of the following items related to the policy and the rules you configured for the policy:

  4. Type any of the following additional information:

  5. Click Display Log. A timestamp, action, rule, and message ID appear for each event.

  6. Click the timestamp link to see the following information:

  7. Perform any of the additional actions:

  1. Choose Logs > Query from the menu.

  2. Next to Type, select MTA events. The query screen for MTA event logs appears.

  3. On the second drop-down menu next to Type, select the IMSVA device to query.

  4. Next to Dates, select a date and time range.

  5. Next to Description, type the keyword to search for.

  6. Click Display Log. A timestamp and MTA event description appears.

  7. Perform any of the additional actions:

  1. Choose Logs > Query from the menu.

  2. Next to Type, select IP filtering. The query screen for MTA event logs appears.

  3. In the second drop-down box next to Type, select one of the following items related to IP Filtering:

  4. Next to Dates, select a date and time range.

  5. Next to IP, provide any IP address to search for.

  6. Click Display Log. Information appears for the time that IMSVA both started and stopped blocking each IP address or domain.

  7. Perform any of the additional actions:

See also:

Configuring Log Settings