I've been working with Darrell from Invariant systems using their log utility.
We've been running AVAFTERJM based on the following logic:
 
We delete about 50% of email as spam via Junkmail (gateway system only).
If we delete 50% of the email then we can reduce the load on Declude/FProt AV by 50% as long as the AV messages are scanned after JM.
 
So, we put AVAFTERJM in the virus.cfg per the instructions.
 
Darrell looked at our logs and found the following: Opened up our DEC and VIR1217.LOG. 
In the VIRlog he found the message Q67df4a0000ae4237 which has a virus. 
Then he went to the DEC1217.LOG and searched for the message and did not find it. 
So, it would seem that AVAFTERJM isn't working properly
 
Thoughts?

Reply via email to