On 12/04/2023 15:09, Syafril Hermansyah via Mdaemon-L wrote:

Kalau hari ini apakah antivirus log dan Content filter log jalan normal?

Untuk hari ini ter-record sampai saya cek di jam 15.19 WIB

tetapi log antivirusnya kenapa terpotong seperti ini ya pak ? saya memang sempat stop mdaemonnya jam 11.15


Wed 2023-04-12 07:29:05.315: * Total attachments removed    : 0
Wed 2023-04-12 07:29:05.356: End of MDaemon AntiVirus results
Wed 2023-04-12 07:29:05.356: ----------
-------------------------------------------------------------------------------
Server Shutdown  Wed, 12 Apr 2023 11:15:38 +0700
-------------------------------------------------------------------------------


START Event Log / MDaemon PRO v23.0.0, AntiVirus log information
-------------------------------------------------------------------------------
Event Time/Date             Event Description
-------------------------------------------------------------------------------
Wed 2023-04-12 11:16:04.276: MDaemon AntiVirus processing c:\mdaemon\queues\local\md35011763771.msg... Wed 2023-04-12 11:16:04.276: * Message return-path: [email protected]

Untuk log content filternya juga sama pak

Wed 2023-04-12 07:29:05.320: Start Content Filter results
Wed 2023-04-12 07:29:05.357: * Matched 0 of 32 active rules
Wed 2023-04-12 07:29:05.357: End of Content Filter results
Wed 2023-04-12 07:29:05.357: ----------
-------------------------------------------------------------------------------
Server Shutdown  Wed, 12 Apr 2023 11:15:38 +0700
-------------------------------------------------------------------------------


START Event Log / MDaemon PRO v23.0.0, Content Filter log information
-------------------------------------------------------------------------------
Event Time/Date             Event Description
-------------------------------------------------------------------------------
Wed 2023-04-12 11:16:04.348: Content Filter processing c:\mdaemon\queues\local\md35011763771.msg... Wed 2023-04-12 11:16:04.348: * Message return-path: [email protected]
Wed 2023-04-12 11:16:04.348: * Message from: [email protected]

Mail Archival apakah diaktifkan sehingga bisa di restore dari situ.

Mohon maaf saya interupt ya pak,

untuk email dari [email protected] hari ini saya sampaikan log-nya sebagai berikut Pak :

SMTP In Log :

Wed 2023-04-12 10:47:13.246: ----------
Wed 2023-04-12 10:47:04.061: [39259586] Session 39259586; child 0005
Wed 2023-04-12 10:47:04.061: [39259586] Accepting SMTP connection from 119.8.177.37:48931 to 103.150.114.155:25 Wed 2023-04-12 10:47:04.062: [39259586] --> 220 mail.persada.id ESMTP MDaemon 23.0.0; Wed, 12 Apr 2023 10:47:04 +0700
Wed 2023-04-12 10:47:04.079: [39259586] <-- EHLO sinmsgout02.his.huawei.com
Wed 2023-04-12 10:47:04.080: [39259586] --> 250-mail.persada.id Hello sinmsgout02.his.huawei.com [119.8.177.37], pleased to meet you
Wed 2023-04-12 10:47:04.080: [39259586] --> 250-ETRN
Wed 2023-04-12 10:47:04.080: [39259586] --> 250-8BITMIME
Wed 2023-04-12 10:47:04.080: [39259586] --> 250-ENHANCEDSTATUSCODES
Wed 2023-04-12 10:47:04.080: [39259586] --> 250-PIPELINING
Wed 2023-04-12 10:47:04.080: [39259586] --> 250-CHUNKING
Wed 2023-04-12 10:47:04.080: [39259586] --> 250-STARTTLS
Wed 2023-04-12 10:47:04.080: [39259586] --> 250 SIZE
Wed 2023-04-12 10:47:04.095: [39259586] <-- STARTTLS
Wed 2023-04-12 10:47:04.095: [39259586] --> 220 2.7.0 Ready to start TLS
Wed 2023-04-12 10:47:04.132: [39259586] SSL negotiation successful (TLS 1.2, TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384)
Wed 2023-04-12 10:47:04.191: [39259586] <-- EHLO sinmsgout02.his.huawei.com
Wed 2023-04-12 10:47:04.191: [39259586] --> 250-mail.persada.id Hello sinmsgout02.his.huawei.com [119.8.177.37], pleased to meet you
Wed 2023-04-12 10:47:04.191: [39259586] --> 250-ETRN
Wed 2023-04-12 10:47:04.191: [39259586] --> 250-8BITMIME
Wed 2023-04-12 10:47:04.191: [39259586] --> 250-ENHANCEDSTATUSCODES
Wed 2023-04-12 10:47:04.191: [39259586] --> 250-PIPELINING
Wed 2023-04-12 10:47:04.191: [39259586] --> 250-CHUNKING
Wed 2023-04-12 10:47:04.191: [39259586] --> 250-REQUIRETLS
Wed 2023-04-12 10:47:04.191: [39259586] --> 250 SIZE
Wed 2023-04-12 10:47:04.209: [39259586] <-- MAIL FROM:<[email protected]> SIZE=35192760 Wed 2023-04-12 10:47:04.220: [39259586] Performing PTR lookup (37.177.8.119.IN-ADDR.ARPA) Wed 2023-04-12 10:47:04.223: [39259586] * D=37.177.8.119.IN-ADDR.ARPA TTL=(0) PTR=[sinmsgout02.his.huawei.com] Wed 2023-04-12 10:47:04.225: [39259586] * D=sinmsgout02.his.huawei.com TTL=(0) A=[119.8.177.37]
Wed 2023-04-12 10:47:04.225: [39259586] ---- End PTR results
Wed 2023-04-12 10:47:04.228: [39259586] Performing IP lookup (sinmsgout02.his.huawei.com) Wed 2023-04-12 10:47:04.230: [39259586] * D=sinmsgout02.his.huawei.com TTL=(0) A=[119.8.177.37]
Wed 2023-04-12 10:47:04.230: [39259586] ---- End IP lookup results
Wed 2023-04-12 10:47:04.237: [39259586] Performing IP lookup (huawei.com)
Wed 2023-04-12 10:47:04.240: [39259586] *  D=huawei.com TTL=(4) A=[121.37.49.12] Wed 2023-04-12 10:47:04.241: [39259586] *  P=010 S=003 D=huawei.com TTL=(9) MX=[mx5.huawei.com] Wed 2023-04-12 10:47:04.241: [39259586] *  P=020 S=001 D=huawei.com TTL=(9) MX=[mx8.his.huawei.com] Wed 2023-04-12 10:47:04.241: [39259586] *  P=030 S=000 D=huawei.com TTL=(9) MX=[mx7.huawei.com] Wed 2023-04-12 10:47:04.241: [39259586] *  P=030 S=002 D=huawei.com TTL=(9) MX=[mx9.his.huawei.com] Wed 2023-04-12 10:47:04.243: [39259586] *  D=mx5.huawei.com TTL=(9) A=[124.71.93.234] Wed 2023-04-12 10:47:04.245: [39259586] *  D=mx8.his.huawei.com TTL=(9) A=[119.8.177.45] Wed 2023-04-12 10:47:04.247: [39259586] *  D=mx7.huawei.com TTL=(9) A=[119.8.89.70] Wed 2023-04-12 10:47:04.250: [39259586] *  D=mx9.his.huawei.com TTL=(9) A=[14.137.139.134]
Wed 2023-04-12 10:47:04.250: [39259586] ---- End IP lookup results
Wed 2023-04-12 10:47:04.254: [39259586] Performing SPF lookup (sinmsgout02.his.huawei.com / 119.8.177.37) Wed 2023-04-12 10:47:04.837: [39259586] *  Result: none; no SPF record in DNS
Wed 2023-04-12 10:47:04.837: [39259586] ---- End SPF results
Wed 2023-04-12 10:47:04.838: [39259586] Performing SPF lookup (huawei.com / 119.8.177.37) Wed 2023-04-12 10:47:04.845: [39259586] *  Policy: v=spf1 ip4:45.249.212.32 ip4:45.249.212.35 ip4:45.249.212.255 ip4:45.249.212.187/29 ip4:45.249.212.191 ip4:168.195.93.47 ip4:185.176.79.56 ip4:119.8.179.247 ip4:119.8.89.136/31 ip4:119.8.89.135 ip4:119.8.177.36/31 ip4:119.8.177.38 -al Wed 2023-04-12 10:47:04.845: [39259586] *  Evaluating ip4:45.249.212.32: no match Wed 2023-04-12 10:47:04.845: [39259586] *  Evaluating ip4:45.249.212.35: no match Wed 2023-04-12 10:47:04.845: [39259586] *  Evaluating ip4:45.249.212.255: no match Wed 2023-04-12 10:47:04.845: [39259586] *  Evaluating ip4:45.249.212.187/29: no match Wed 2023-04-12 10:47:04.845: [39259586] *  Evaluating ip4:45.249.212.191: no match Wed 2023-04-12 10:47:04.845: [39259586] *  Evaluating ip4:168.195.93.47: no match Wed 2023-04-12 10:47:04.845: [39259586] *  Evaluating ip4:185.176.79.56: no match Wed 2023-04-12 10:47:04.845: [39259586] *  Evaluating ip4:119.8.179.247: no match Wed 2023-04-12 10:47:04.845: [39259586] *  Evaluating ip4:119.8.89.136/31: no match Wed 2023-04-12 10:47:04.845: [39259586] *  Evaluating ip4:119.8.89.135: no match Wed 2023-04-12 10:47:04.845: [39259586] *  Evaluating ip4:119.8.177.36/31: match
Wed 2023-04-12 10:47:04.845: [39259586] *  Result: pass
Wed 2023-04-12 10:47:04.845: [39259586] ---- End SPF results
Wed 2023-04-12 10:47:04.846: [39259586] --> 250 2.1.0 Sender OK
Wed 2023-04-12 10:47:04.846: [39259586] <-- RCPT TO:<[email protected]> Wed 2023-04-12 10:47:04.849: [39259586] [email protected] is an alias for [email protected] Wed 2023-04-12 10:47:04.858: [39259586] Performing DNS-BL lookup (119.8.177.37 - connecting IP)
Wed 2023-04-12 10:47:04.950: [39259586] *  bl.spamcop.net - passed
Wed 2023-04-12 10:47:04.950: [39259586] ---- End DNS-BL results
Wed 2023-04-12 10:47:04.954: [39259586] --> 250 2.1.5 Recipient OK
Wed 2023-04-12 10:47:04.955: [39259586] <-- RCPT TO:<[email protected]>
Wed 2023-04-12 10:47:04.964: [39259586] --> 250 2.1.5 Recipient OK
Wed 2023-04-12 10:47:04.964: [39259586] <-- RCPT TO:<[email protected]>
Wed 2023-04-12 10:47:04.973: [39259586] --> 250 2.1.5 Recipient OK
Wed 2023-04-12 10:47:04.974: [39259586] <-- RCPT TO:<[email protected]> Wed 2023-04-12 10:47:04.977: [39259586] [email protected] is an alias for [email protected]
Wed 2023-04-12 10:47:04.983: [39259586] --> 250 2.1.5 Recipient OK
Wed 2023-04-12 10:47:04.983: [39259586] <-- RCPT TO:<[email protected]> Wed 2023-04-12 10:47:04.986: [39259586] [email protected] is an alias for [email protected]
Wed 2023-04-12 10:47:04.992: [39259586] --> 250 2.1.5 Recipient OK
Wed 2023-04-12 10:47:04.992: [39259586] <-- RCPT TO:<[email protected]> Wed 2023-04-12 10:47:04.995: [39259586] [email protected] is an alias for [email protected]
Wed 2023-04-12 10:47:05.001: [39259586] --> 250 2.1.5 Recipient OK
Wed 2023-04-12 10:47:05.001: [39259586] <-- RCPT TO:<[email protected]> Wed 2023-04-12 10:47:05.004: [39259586] [email protected] is an alias for [email protected]
Wed 2023-04-12 10:47:05.010: [39259586] --> 250 2.1.5 Recipient OK
Wed 2023-04-12 10:47:05.010: [39259586] <-- RCPT TO:<[email protected]>
Wed 2023-04-12 10:47:05.020: [39259586] --> 250 2.1.5 Recipient OK
Wed 2023-04-12 10:47:05.020: [39259586] <-- RCPT TO:<[email protected]>
Wed 2023-04-12 10:47:05.056: [39259586] --> 250 2.1.5 Recipient OK
Wed 2023-04-12 10:47:05.057: [39259586] <-- RCPT TO:<[email protected]>
Wed 2023-04-12 10:47:05.066: [39259586] --> 250 2.1.5 Recipient OK
Wed 2023-04-12 10:47:05.066: [39259586] <-- RCPT TO:<[email protected]> Wed 2023-04-12 10:47:05.069: [39259586] [email protected] is an alias for [email protected]
Wed 2023-04-12 10:47:05.076: [39259586] --> 250 2.1.5 Recipient OK
Wed 2023-04-12 10:47:05.076: [39259586] <-- RCPT TO:<[email protected]> Wed 2023-04-12 10:47:05.079: [39259586] [email protected] is an alias for [email protected]
Wed 2023-04-12 10:47:05.085: [39259586] --> 250 2.1.5 Recipient OK
Wed 2023-04-12 10:47:05.085: [39259586] <-- RCPT TO:<[email protected]> Wed 2023-04-12 10:47:05.088: [39259586] [email protected] is an alias for [email protected]
Wed 2023-04-12 10:47:05.094: [39259586] --> 250 2.1.5 Recipient OK
Wed 2023-04-12 10:47:05.094: [39259586] <-- RCPT TO:<[email protected]> Wed 2023-04-12 10:47:05.097: [39259586] [email protected] is an alias for [email protected]
Wed 2023-04-12 10:47:05.103: [39259586] --> 250 2.1.5 Recipient OK
Wed 2023-04-12 10:47:05.103: [39259586] <-- RCPT TO:<[email protected]> Wed 2023-04-12 10:47:05.106: [39259586] [email protected] is an alias for [email protected]
Wed 2023-04-12 10:47:05.112: [39259586] --> 250 2.1.5 Recipient OK
Wed 2023-04-12 10:47:05.112: [39259586] <-- RCPT TO:<[email protected]> Wed 2023-04-12 10:47:05.115: [39259586] [email protected] is an alias for [email protected]
Wed 2023-04-12 10:47:05.121: [39259586] --> 250 2.1.5 Recipient OK
Wed 2023-04-12 10:47:05.121: [39259586] <-- RCPT TO:<[email protected]> Wed 2023-04-12 10:47:05.124: [39259586] [email protected] is an alias for [email protected]
Wed 2023-04-12 10:47:05.130: [39259586] --> 250 2.1.5 Recipient OK
Wed 2023-04-12 10:47:05.130: [39259586] <-- RCPT TO:<[email protected]>
Wed 2023-04-12 10:47:05.139: [39259586] --> 250 2.1.5 Recipient OK
Wed 2023-04-12 10:47:05.139: [39259586] <-- RCPT TO:<[email protected]>
Wed 2023-04-12 10:47:05.148: [39259586] --> 250 2.1.5 Recipient OK
Wed 2023-04-12 10:47:05.148: [39259586] <-- RCPT TO:<[email protected]>
Wed 2023-04-12 10:47:05.158: [39259586] --> 250 2.1.5 Recipient OK
Wed 2023-04-12 10:47:05.159: [39259586] <-- RCPT TO:<[email protected]> Wed 2023-04-12 10:47:05.162: [39259586] [email protected] is an alias for [email protected]
Wed 2023-04-12 10:47:05.168: [39259586] --> 250 2.1.5 Recipient OK
Wed 2023-04-12 10:47:05.168: [39259586] <-- RCPT TO:<[email protected]>
Wed 2023-04-12 10:47:05.178: [39259586] --> 250 2.1.5 Recipient OK
Wed 2023-04-12 10:47:05.178: [39259586] <-- RCPT TO:<[email protected]> Wed 2023-04-12 10:47:05.181: [39259586] [email protected] is an alias for [email protected]
Wed 2023-04-12 10:47:05.187: [39259586] --> 250 2.1.5 Recipient OK
Wed 2023-04-12 10:47:05.187: [39259586] <-- RCPT TO:<[email protected]>
Wed 2023-04-12 10:47:05.196: [39259586] --> 250 2.1.5 Recipient OK
Wed 2023-04-12 10:47:05.196: [39259586] <-- RCPT TO:<[email protected]>
Wed 2023-04-12 10:47:05.206: [39259586] --> 250 2.1.5 Recipient OK
Wed 2023-04-12 10:47:05.206: [39259586] <-- RCPT TO:<[email protected]>
Wed 2023-04-12 10:47:05.216: [39259586] --> 250 2.1.5 Recipient OK
Wed 2023-04-12 10:47:05.216: [39259586] <-- RCPT TO:<[email protected]>
Wed 2023-04-12 10:47:05.219: [39259586] [email protected] is an alias for [email protected]
Wed 2023-04-12 10:47:05.226: [39259586] --> 250 2.1.5 Recipient OK
Wed 2023-04-12 10:47:05.226: [39259586] <-- RCPT TO:<[email protected]> Wed 2023-04-12 10:47:05.230: [39259586] [email protected] is an alias for [email protected]
Wed 2023-04-12 10:47:05.236: [39259586] --> 250 2.1.5 Recipient OK
Wed 2023-04-12 10:47:05.236: [39259586] <-- RCPT TO:<[email protected]>
Wed 2023-04-12 10:47:05.242: [39259586] Sender attempted to deliver message to unknown address Wed 2023-04-12 10:47:05.242: [39259586] --> 550 5.1.1 Recipient unknown <[email protected]>
Wed 2023-04-12 10:47:05.242: [39259586] <-- RCPT TO:<[email protected]>
Wed 2023-04-12 10:47:05.245: [39259586] [email protected] is an alias for [email protected]
Wed 2023-04-12 10:47:05.251: [39259586] --> 250 2.1.5 Recipient OK
Wed 2023-04-12 10:47:05.251: [39259586] <-- RCPT TO:<[email protected]>
Wed 2023-04-12 10:47:05.261: [39259586] --> 250 2.1.5 Recipient OK
Wed 2023-04-12 10:47:05.261: [39259586] <-- DATA
Wed 2023-04-12 10:47:05.263: [39259586] --> 354 Enter mail, end with <CRLF>.<CRLF>
Wed 2023-04-12 10:47:13.138: [39259586] Message size: 35192726 bytes
Wed 2023-04-12 10:47:13.221: [39259586] Performing DKIM verification
Wed 2023-04-12 10:47:13.221: [39259586] *  File: c:\mdaemon\queues\temp\md50000097659.tmp Wed 2023-04-12 10:47:13.221: [39259586] *  Message-ID: <[email protected]>
Wed 2023-04-12 10:47:13.222: [39259586] *  Result: neutral
Wed 2023-04-12 10:47:13.222: [39259586] ---- End DKIM results
Wed 2023-04-12 10:47:13.229: [39259586] Performing DMARC processing
Wed 2023-04-12 10:47:13.229: [39259586] *  File: c:\mdaemon\queues\temp\md50000097659.tmp Wed 2023-04-12 10:47:13.229: [39259586] *  Message-ID: <[email protected]>
Wed 2023-04-12 10:47:13.229: [39259586] *  Author domain: huawei.com
Wed 2023-04-12 10:47:13.229: [39259586] *  Organizational domain: huawei.com
Wed 2023-04-12 10:47:13.229: [39259586] *  Query domain: _dmarc.huawei.com
Wed 2023-04-12 10:47:13.232: [39259586] *    Policy record: v=DMARC1;p=quarantine;ruf=mailto:[email protected];rua=mailto:[email protected] Wed 2023-04-12 10:47:13.246: [39259586] *  Checking authentication mechanisms for DMARC alignment Wed 2023-04-12 10:47:13.246: [39259586] *    SPF: domain "huawei.com" passed SPF check; and domain is DMARC aligned
Wed 2023-04-12 10:47:13.246: [39259586] *    DKIM: no DKIM signatures found
Wed 2023-04-12 10:47:13.246: [39259586] *  Result: pass
Wed 2023-04-12 10:47:13.246: [39259586] ---- End DMARC results
Wed 2023-04-12 10:47:13.305: [39259586] Passing message through AntiVirus (Size: 35192726)... Wed 2023-04-12 10:47:13.305: [39259586] *  Message was not scanned inline, it is too big
Wed 2023-04-12 10:47:13.306: [39259586] ---- End AntiVirus results
Wed 2023-04-12 10:47:13.344: [39259586] Message creation successful: c:\mdaemon\queues\inbound\md50006371475.msg Wed 2023-04-12 10:47:13.344: [39259586] --> 250 2.6.0 Ok, message saved <Message-ID: <[email protected]>>
Wed 2023-04-12 10:47:13.345: [39259586] <-- QUIT
Wed 2023-04-12 10:47:13.345: [39259586] --> 221 2.0.0 See ya in cyberspace
Wed 2023-04-12 10:47:13.346: [39259586] SMTP session successful (Bytes in/out: 35443798/2659)
Wed 2023-04-12 10:47:13.354: ----------

Routing Log :

Wed 2023-04-12 10:47:12.463: 12: ----------
Wed 2023-04-12 10:47:47.385: 17: INBOUND message: md50006371475.msg
Wed 2023-04-12 10:47:47.385: 17: *  From: IOHReporting1 <[email protected]> Wed 2023-04-12 10:47:47.385: 17: *  To: IOHReporting1 <[email protected]>, "[email protected]" <[email protected]>, "[email protected]" <[email protected]>, 'Helpdesk Adyawinsa' <[email protected]>, 'Herwin S Tarigan' Wed 2023-04-12 10:47:47.385: 17: *  Subject: P1_ANOD_149_H3I_NetworkOperationDailyReport_IOHMS-20230412 Wed 2023-04-12 10:47:47.385: 17: *  Message-ID: <[email protected]> Wed 2023-04-12 10:47:47.385: 17: *  Modified From: "IOHReporting1 ([email protected])" <[email protected]> Wed 2023-04-12 10:47:47.385: 17: *  Size: 35194184; <c:\mdaemon\queues\local\md50011763196.msg>
Wed 2023-04-12 10:47:47.385: 17: ----------

Untuk di log antivirus dan content filter tidak saya temukan karena terpotong di jam pengiriman pak, saya cari di archive log belum ter-create dua log tersebut.


Untuk log smtp in diatas kasusnya seperti ini pak, email dari [email protected] terkirim ke alamat alias yang saya buat, tetapi tidak ada di inbox/mailbox [email protected] atau [email protected] yang masih ada/aktif account-nya pak.


Terima kasih

--
--[mdaemon-l]----------------------------------------------------------
Milis ini untuk Diskusi antar pengguna MDaemon Mail Server di Indonesia

Netiket: https://wiki.openstack.org/wiki/MailingListEtiquette
Arsip: http://mdaemon-l.dutaint.com
Dokumentasi : http://mdaemon.dutaint.co.id
Berlangganan: Kirim mail ke [email protected]
Henti Langgan: Kirim mail ke [email protected]
Versi terakhir: MDaemon 23.0.0, SecurityGateway 9.0.1


Kirim email ke