On 12/04/2023 15:09, Syafril Hermansyah via Mdaemon-L wrote:
Kalau hari ini apakah antivirus log dan Content filter log jalan normal?
Untuk hari ini ter-record sampai saya cek di jam 15.19 WIB
tetapi log antivirusnya kenapa terpotong seperti ini ya pak ? saya
memang sempat stop mdaemonnya jam 11.15
Wed 2023-04-12 07:29:05.315: * Total attachments removed : 0
Wed 2023-04-12 07:29:05.356: End of MDaemon AntiVirus results
Wed 2023-04-12 07:29:05.356: ----------
-------------------------------------------------------------------------------
Server Shutdown Wed, 12 Apr 2023 11:15:38 +0700
-------------------------------------------------------------------------------
START Event Log / MDaemon PRO v23.0.0, AntiVirus log information
-------------------------------------------------------------------------------
Event Time/Date Event Description
-------------------------------------------------------------------------------
Wed 2023-04-12 11:16:04.276: MDaemon AntiVirus processing
c:\mdaemon\queues\local\md35011763771.msg...
Wed 2023-04-12 11:16:04.276: * Message return-path:
[email protected]
Untuk log content filternya juga sama pak
Wed 2023-04-12 07:29:05.320: Start Content Filter results
Wed 2023-04-12 07:29:05.357: * Matched 0 of 32 active rules
Wed 2023-04-12 07:29:05.357: End of Content Filter results
Wed 2023-04-12 07:29:05.357: ----------
-------------------------------------------------------------------------------
Server Shutdown Wed, 12 Apr 2023 11:15:38 +0700
-------------------------------------------------------------------------------
START Event Log / MDaemon PRO v23.0.0, Content Filter log information
-------------------------------------------------------------------------------
Event Time/Date Event Description
-------------------------------------------------------------------------------
Wed 2023-04-12 11:16:04.348: Content Filter processing
c:\mdaemon\queues\local\md35011763771.msg...
Wed 2023-04-12 11:16:04.348: * Message return-path:
[email protected]
Wed 2023-04-12 11:16:04.348: * Message from: [email protected]
Mail Archival apakah diaktifkan sehingga bisa di restore dari situ.
Mohon maaf saya interupt ya pak,
untuk email dari [email protected] hari ini saya sampaikan log-nya
sebagai berikut Pak :
SMTP In Log :
Wed 2023-04-12 10:47:13.246: ----------
Wed 2023-04-12 10:47:04.061: [39259586] Session 39259586; child 0005
Wed 2023-04-12 10:47:04.061: [39259586] Accepting SMTP connection from
119.8.177.37:48931 to 103.150.114.155:25
Wed 2023-04-12 10:47:04.062: [39259586] --> 220 mail.persada.id ESMTP
MDaemon 23.0.0; Wed, 12 Apr 2023 10:47:04 +0700
Wed 2023-04-12 10:47:04.079: [39259586] <-- EHLO sinmsgout02.his.huawei.com
Wed 2023-04-12 10:47:04.080: [39259586] --> 250-mail.persada.id Hello
sinmsgout02.his.huawei.com [119.8.177.37], pleased to meet you
Wed 2023-04-12 10:47:04.080: [39259586] --> 250-ETRN
Wed 2023-04-12 10:47:04.080: [39259586] --> 250-8BITMIME
Wed 2023-04-12 10:47:04.080: [39259586] --> 250-ENHANCEDSTATUSCODES
Wed 2023-04-12 10:47:04.080: [39259586] --> 250-PIPELINING
Wed 2023-04-12 10:47:04.080: [39259586] --> 250-CHUNKING
Wed 2023-04-12 10:47:04.080: [39259586] --> 250-STARTTLS
Wed 2023-04-12 10:47:04.080: [39259586] --> 250 SIZE
Wed 2023-04-12 10:47:04.095: [39259586] <-- STARTTLS
Wed 2023-04-12 10:47:04.095: [39259586] --> 220 2.7.0 Ready to start TLS
Wed 2023-04-12 10:47:04.132: [39259586] SSL negotiation successful (TLS
1.2, TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384)
Wed 2023-04-12 10:47:04.191: [39259586] <-- EHLO sinmsgout02.his.huawei.com
Wed 2023-04-12 10:47:04.191: [39259586] --> 250-mail.persada.id Hello
sinmsgout02.his.huawei.com [119.8.177.37], pleased to meet you
Wed 2023-04-12 10:47:04.191: [39259586] --> 250-ETRN
Wed 2023-04-12 10:47:04.191: [39259586] --> 250-8BITMIME
Wed 2023-04-12 10:47:04.191: [39259586] --> 250-ENHANCEDSTATUSCODES
Wed 2023-04-12 10:47:04.191: [39259586] --> 250-PIPELINING
Wed 2023-04-12 10:47:04.191: [39259586] --> 250-CHUNKING
Wed 2023-04-12 10:47:04.191: [39259586] --> 250-REQUIRETLS
Wed 2023-04-12 10:47:04.191: [39259586] --> 250 SIZE
Wed 2023-04-12 10:47:04.209: [39259586] <-- MAIL
FROM:<[email protected]> SIZE=35192760
Wed 2023-04-12 10:47:04.220: [39259586] Performing PTR lookup
(37.177.8.119.IN-ADDR.ARPA)
Wed 2023-04-12 10:47:04.223: [39259586] * D=37.177.8.119.IN-ADDR.ARPA
TTL=(0) PTR=[sinmsgout02.his.huawei.com]
Wed 2023-04-12 10:47:04.225: [39259586] * D=sinmsgout02.his.huawei.com
TTL=(0) A=[119.8.177.37]
Wed 2023-04-12 10:47:04.225: [39259586] ---- End PTR results
Wed 2023-04-12 10:47:04.228: [39259586] Performing IP lookup
(sinmsgout02.his.huawei.com)
Wed 2023-04-12 10:47:04.230: [39259586] * D=sinmsgout02.his.huawei.com
TTL=(0) A=[119.8.177.37]
Wed 2023-04-12 10:47:04.230: [39259586] ---- End IP lookup results
Wed 2023-04-12 10:47:04.237: [39259586] Performing IP lookup (huawei.com)
Wed 2023-04-12 10:47:04.240: [39259586] * D=huawei.com TTL=(4)
A=[121.37.49.12]
Wed 2023-04-12 10:47:04.241: [39259586] * P=010 S=003 D=huawei.com
TTL=(9) MX=[mx5.huawei.com]
Wed 2023-04-12 10:47:04.241: [39259586] * P=020 S=001 D=huawei.com
TTL=(9) MX=[mx8.his.huawei.com]
Wed 2023-04-12 10:47:04.241: [39259586] * P=030 S=000 D=huawei.com
TTL=(9) MX=[mx7.huawei.com]
Wed 2023-04-12 10:47:04.241: [39259586] * P=030 S=002 D=huawei.com
TTL=(9) MX=[mx9.his.huawei.com]
Wed 2023-04-12 10:47:04.243: [39259586] * D=mx5.huawei.com TTL=(9)
A=[124.71.93.234]
Wed 2023-04-12 10:47:04.245: [39259586] * D=mx8.his.huawei.com TTL=(9)
A=[119.8.177.45]
Wed 2023-04-12 10:47:04.247: [39259586] * D=mx7.huawei.com TTL=(9)
A=[119.8.89.70]
Wed 2023-04-12 10:47:04.250: [39259586] * D=mx9.his.huawei.com TTL=(9)
A=[14.137.139.134]
Wed 2023-04-12 10:47:04.250: [39259586] ---- End IP lookup results
Wed 2023-04-12 10:47:04.254: [39259586] Performing SPF lookup
(sinmsgout02.his.huawei.com / 119.8.177.37)
Wed 2023-04-12 10:47:04.837: [39259586] * Result: none; no SPF record
in DNS
Wed 2023-04-12 10:47:04.837: [39259586] ---- End SPF results
Wed 2023-04-12 10:47:04.838: [39259586] Performing SPF lookup
(huawei.com / 119.8.177.37)
Wed 2023-04-12 10:47:04.845: [39259586] * Policy: v=spf1
ip4:45.249.212.32 ip4:45.249.212.35 ip4:45.249.212.255
ip4:45.249.212.187/29 ip4:45.249.212.191 ip4:168.195.93.47
ip4:185.176.79.56 ip4:119.8.179.247 ip4:119.8.89.136/31 ip4:119.8.89.135
ip4:119.8.177.36/31 ip4:119.8.177.38 -al
Wed 2023-04-12 10:47:04.845: [39259586] * Evaluating ip4:45.249.212.32:
no match
Wed 2023-04-12 10:47:04.845: [39259586] * Evaluating ip4:45.249.212.35:
no match
Wed 2023-04-12 10:47:04.845: [39259586] * Evaluating
ip4:45.249.212.255: no match
Wed 2023-04-12 10:47:04.845: [39259586] * Evaluating
ip4:45.249.212.187/29: no match
Wed 2023-04-12 10:47:04.845: [39259586] * Evaluating
ip4:45.249.212.191: no match
Wed 2023-04-12 10:47:04.845: [39259586] * Evaluating ip4:168.195.93.47:
no match
Wed 2023-04-12 10:47:04.845: [39259586] * Evaluating ip4:185.176.79.56:
no match
Wed 2023-04-12 10:47:04.845: [39259586] * Evaluating ip4:119.8.179.247:
no match
Wed 2023-04-12 10:47:04.845: [39259586] * Evaluating
ip4:119.8.89.136/31: no match
Wed 2023-04-12 10:47:04.845: [39259586] * Evaluating ip4:119.8.89.135:
no match
Wed 2023-04-12 10:47:04.845: [39259586] * Evaluating
ip4:119.8.177.36/31: match
Wed 2023-04-12 10:47:04.845: [39259586] * Result: pass
Wed 2023-04-12 10:47:04.845: [39259586] ---- End SPF results
Wed 2023-04-12 10:47:04.846: [39259586] --> 250 2.1.0 Sender OK
Wed 2023-04-12 10:47:04.846: [39259586] <-- RCPT
TO:<[email protected]>
Wed 2023-04-12 10:47:04.849: [39259586] [email protected] is an
alias for [email protected]
Wed 2023-04-12 10:47:04.858: [39259586] Performing DNS-BL lookup
(119.8.177.37 - connecting IP)
Wed 2023-04-12 10:47:04.950: [39259586] * bl.spamcop.net - passed
Wed 2023-04-12 10:47:04.950: [39259586] ---- End DNS-BL results
Wed 2023-04-12 10:47:04.954: [39259586] --> 250 2.1.5 Recipient OK
Wed 2023-04-12 10:47:04.955: [39259586] <-- RCPT TO:<[email protected]>
Wed 2023-04-12 10:47:04.964: [39259586] --> 250 2.1.5 Recipient OK
Wed 2023-04-12 10:47:04.964: [39259586] <-- RCPT TO:<[email protected]>
Wed 2023-04-12 10:47:04.973: [39259586] --> 250 2.1.5 Recipient OK
Wed 2023-04-12 10:47:04.974: [39259586] <-- RCPT
TO:<[email protected]>
Wed 2023-04-12 10:47:04.977: [39259586] [email protected]
is an alias for [email protected]
Wed 2023-04-12 10:47:04.983: [39259586] --> 250 2.1.5 Recipient OK
Wed 2023-04-12 10:47:04.983: [39259586] <-- RCPT
TO:<[email protected]>
Wed 2023-04-12 10:47:04.986: [39259586] [email protected] is
an alias for [email protected]
Wed 2023-04-12 10:47:04.992: [39259586] --> 250 2.1.5 Recipient OK
Wed 2023-04-12 10:47:04.992: [39259586] <-- RCPT
TO:<[email protected]>
Wed 2023-04-12 10:47:04.995: [39259586] [email protected] is an
alias for [email protected]
Wed 2023-04-12 10:47:05.001: [39259586] --> 250 2.1.5 Recipient OK
Wed 2023-04-12 10:47:05.001: [39259586] <-- RCPT
TO:<[email protected]>
Wed 2023-04-12 10:47:05.004: [39259586] [email protected] is
an alias for [email protected]
Wed 2023-04-12 10:47:05.010: [39259586] --> 250 2.1.5 Recipient OK
Wed 2023-04-12 10:47:05.010: [39259586] <-- RCPT
TO:<[email protected]>
Wed 2023-04-12 10:47:05.020: [39259586] --> 250 2.1.5 Recipient OK
Wed 2023-04-12 10:47:05.020: [39259586] <-- RCPT TO:<[email protected]>
Wed 2023-04-12 10:47:05.056: [39259586] --> 250 2.1.5 Recipient OK
Wed 2023-04-12 10:47:05.057: [39259586] <-- RCPT
TO:<[email protected]>
Wed 2023-04-12 10:47:05.066: [39259586] --> 250 2.1.5 Recipient OK
Wed 2023-04-12 10:47:05.066: [39259586] <-- RCPT
TO:<[email protected]>
Wed 2023-04-12 10:47:05.069: [39259586] [email protected] is an
alias for [email protected]
Wed 2023-04-12 10:47:05.076: [39259586] --> 250 2.1.5 Recipient OK
Wed 2023-04-12 10:47:05.076: [39259586] <-- RCPT
TO:<[email protected]>
Wed 2023-04-12 10:47:05.079: [39259586] [email protected] is an
alias for [email protected]
Wed 2023-04-12 10:47:05.085: [39259586] --> 250 2.1.5 Recipient OK
Wed 2023-04-12 10:47:05.085: [39259586] <-- RCPT
TO:<[email protected]>
Wed 2023-04-12 10:47:05.088: [39259586] [email protected] is an
alias for [email protected]
Wed 2023-04-12 10:47:05.094: [39259586] --> 250 2.1.5 Recipient OK
Wed 2023-04-12 10:47:05.094: [39259586] <-- RCPT
TO:<[email protected]>
Wed 2023-04-12 10:47:05.097: [39259586]
[email protected] is an alias for
[email protected]
Wed 2023-04-12 10:47:05.103: [39259586] --> 250 2.1.5 Recipient OK
Wed 2023-04-12 10:47:05.103: [39259586] <-- RCPT
TO:<[email protected]>
Wed 2023-04-12 10:47:05.106: [39259586]
[email protected] is an alias for
[email protected]
Wed 2023-04-12 10:47:05.112: [39259586] --> 250 2.1.5 Recipient OK
Wed 2023-04-12 10:47:05.112: [39259586] <-- RCPT
TO:<[email protected]>
Wed 2023-04-12 10:47:05.115: [39259586]
[email protected] is an alias for
[email protected]
Wed 2023-04-12 10:47:05.121: [39259586] --> 250 2.1.5 Recipient OK
Wed 2023-04-12 10:47:05.121: [39259586] <-- RCPT
TO:<[email protected]>
Wed 2023-04-12 10:47:05.124: [39259586] [email protected] is an
alias for [email protected]
Wed 2023-04-12 10:47:05.130: [39259586] --> 250 2.1.5 Recipient OK
Wed 2023-04-12 10:47:05.130: [39259586] <-- RCPT TO:<[email protected]>
Wed 2023-04-12 10:47:05.139: [39259586] --> 250 2.1.5 Recipient OK
Wed 2023-04-12 10:47:05.139: [39259586] <-- RCPT
TO:<[email protected]>
Wed 2023-04-12 10:47:05.148: [39259586] --> 250 2.1.5 Recipient OK
Wed 2023-04-12 10:47:05.148: [39259586] <-- RCPT
TO:<[email protected]>
Wed 2023-04-12 10:47:05.158: [39259586] --> 250 2.1.5 Recipient OK
Wed 2023-04-12 10:47:05.159: [39259586] <-- RCPT
TO:<[email protected]>
Wed 2023-04-12 10:47:05.162: [39259586] [email protected] is an
alias for [email protected]
Wed 2023-04-12 10:47:05.168: [39259586] --> 250 2.1.5 Recipient OK
Wed 2023-04-12 10:47:05.168: [39259586] <-- RCPT
TO:<[email protected]>
Wed 2023-04-12 10:47:05.178: [39259586] --> 250 2.1.5 Recipient OK
Wed 2023-04-12 10:47:05.178: [39259586] <-- RCPT
TO:<[email protected]>
Wed 2023-04-12 10:47:05.181: [39259586] [email protected] is an
alias for [email protected]
Wed 2023-04-12 10:47:05.187: [39259586] --> 250 2.1.5 Recipient OK
Wed 2023-04-12 10:47:05.187: [39259586] <-- RCPT
TO:<[email protected]>
Wed 2023-04-12 10:47:05.196: [39259586] --> 250 2.1.5 Recipient OK
Wed 2023-04-12 10:47:05.196: [39259586] <-- RCPT TO:<[email protected]>
Wed 2023-04-12 10:47:05.206: [39259586] --> 250 2.1.5 Recipient OK
Wed 2023-04-12 10:47:05.206: [39259586] <-- RCPT
TO:<[email protected]>
Wed 2023-04-12 10:47:05.216: [39259586] --> 250 2.1.5 Recipient OK
Wed 2023-04-12 10:47:05.216: [39259586] <-- RCPT TO:<[email protected]>
Wed 2023-04-12 10:47:05.219: [39259586] [email protected] is an
alias for [email protected]
Wed 2023-04-12 10:47:05.226: [39259586] --> 250 2.1.5 Recipient OK
Wed 2023-04-12 10:47:05.226: [39259586] <-- RCPT
TO:<[email protected]>
Wed 2023-04-12 10:47:05.230: [39259586] [email protected] is an
alias for [email protected]
Wed 2023-04-12 10:47:05.236: [39259586] --> 250 2.1.5 Recipient OK
Wed 2023-04-12 10:47:05.236: [39259586] <-- RCPT TO:<[email protected]>
Wed 2023-04-12 10:47:05.242: [39259586] Sender attempted to deliver
message to unknown address
Wed 2023-04-12 10:47:05.242: [39259586] --> 550 5.1.1 Recipient unknown
<[email protected]>
Wed 2023-04-12 10:47:05.242: [39259586] <-- RCPT TO:<[email protected]>
Wed 2023-04-12 10:47:05.245: [39259586] [email protected] is an alias
for [email protected]
Wed 2023-04-12 10:47:05.251: [39259586] --> 250 2.1.5 Recipient OK
Wed 2023-04-12 10:47:05.251: [39259586] <-- RCPT
TO:<[email protected]>
Wed 2023-04-12 10:47:05.261: [39259586] --> 250 2.1.5 Recipient OK
Wed 2023-04-12 10:47:05.261: [39259586] <-- DATA
Wed 2023-04-12 10:47:05.263: [39259586] --> 354 Enter mail, end with
<CRLF>.<CRLF>
Wed 2023-04-12 10:47:13.138: [39259586] Message size: 35192726 bytes
Wed 2023-04-12 10:47:13.221: [39259586] Performing DKIM verification
Wed 2023-04-12 10:47:13.221: [39259586] * File:
c:\mdaemon\queues\temp\md50000097659.tmp
Wed 2023-04-12 10:47:13.221: [39259586] * Message-ID:
<[email protected]>
Wed 2023-04-12 10:47:13.222: [39259586] * Result: neutral
Wed 2023-04-12 10:47:13.222: [39259586] ---- End DKIM results
Wed 2023-04-12 10:47:13.229: [39259586] Performing DMARC processing
Wed 2023-04-12 10:47:13.229: [39259586] * File:
c:\mdaemon\queues\temp\md50000097659.tmp
Wed 2023-04-12 10:47:13.229: [39259586] * Message-ID:
<[email protected]>
Wed 2023-04-12 10:47:13.229: [39259586] * Author domain: huawei.com
Wed 2023-04-12 10:47:13.229: [39259586] * Organizational domain: huawei.com
Wed 2023-04-12 10:47:13.229: [39259586] * Query domain: _dmarc.huawei.com
Wed 2023-04-12 10:47:13.232: [39259586] * Policy record:
v=DMARC1;p=quarantine;ruf=mailto:[email protected];rua=mailto:[email protected]
Wed 2023-04-12 10:47:13.246: [39259586] * Checking authentication
mechanisms for DMARC alignment
Wed 2023-04-12 10:47:13.246: [39259586] * SPF: domain "huawei.com"
passed SPF check; and domain is DMARC aligned
Wed 2023-04-12 10:47:13.246: [39259586] * DKIM: no DKIM signatures found
Wed 2023-04-12 10:47:13.246: [39259586] * Result: pass
Wed 2023-04-12 10:47:13.246: [39259586] ---- End DMARC results
Wed 2023-04-12 10:47:13.305: [39259586] Passing message through
AntiVirus (Size: 35192726)...
Wed 2023-04-12 10:47:13.305: [39259586] * Message was not scanned
inline, it is too big
Wed 2023-04-12 10:47:13.306: [39259586] ---- End AntiVirus results
Wed 2023-04-12 10:47:13.344: [39259586] Message creation successful:
c:\mdaemon\queues\inbound\md50006371475.msg
Wed 2023-04-12 10:47:13.344: [39259586] --> 250 2.6.0 Ok, message saved
<Message-ID: <[email protected]>>
Wed 2023-04-12 10:47:13.345: [39259586] <-- QUIT
Wed 2023-04-12 10:47:13.345: [39259586] --> 221 2.0.0 See ya in cyberspace
Wed 2023-04-12 10:47:13.346: [39259586] SMTP session successful (Bytes
in/out: 35443798/2659)
Wed 2023-04-12 10:47:13.354: ----------
Routing Log :
Wed 2023-04-12 10:47:12.463: 12: ----------
Wed 2023-04-12 10:47:47.385: 17: INBOUND message: md50006371475.msg
Wed 2023-04-12 10:47:47.385: 17: * From: IOHReporting1
<[email protected]>
Wed 2023-04-12 10:47:47.385: 17: * To: IOHReporting1
<[email protected]>, "[email protected]"
<[email protected]>, "[email protected]"
<[email protected]>, 'Helpdesk Adyawinsa'
<[email protected]>, 'Herwin S Tarigan'
Wed 2023-04-12 10:47:47.385: 17: * Subject:
P1_ANOD_149_H3I_NetworkOperationDailyReport_IOHMS-20230412
Wed 2023-04-12 10:47:47.385: 17: * Message-ID:
<[email protected]>
Wed 2023-04-12 10:47:47.385: 17: * Modified From: "IOHReporting1
([email protected])" <[email protected]>
Wed 2023-04-12 10:47:47.385: 17: * Size: 35194184;
<c:\mdaemon\queues\local\md50011763196.msg>
Wed 2023-04-12 10:47:47.385: 17: ----------
Untuk di log antivirus dan content filter tidak saya temukan karena
terpotong di jam pengiriman pak, saya cari di archive log belum
ter-create dua log tersebut.
Untuk log smtp in diatas kasusnya seperti ini pak, email dari
[email protected] terkirim ke alamat alias yang saya buat, tetapi
tidak ada di inbox/mailbox [email protected] atau
[email protected] yang masih ada/aktif account-nya pak.
Terima kasih
--
--[mdaemon-l]----------------------------------------------------------
Milis ini untuk Diskusi antar pengguna MDaemon Mail Server di Indonesia
Netiket: https://wiki.openstack.org/wiki/MailingListEtiquette
Arsip: http://mdaemon-l.dutaint.com
Dokumentasi : http://mdaemon.dutaint.co.id
Berlangganan: Kirim mail ke [email protected]
Henti Langgan: Kirim mail ke [email protected]
Versi terakhir: MDaemon 23.0.0, SecurityGateway 9.0.1