Hi Andrew, Sure! Here is a clipping (with identifyable info changed) that contains a valid, delivered email, some spam and a timesheet record.
Mon 2008-10-20 10:00:31: ---------- Mon 2008-10-20 10:00:32: Session 2698; child 2; thread 2204 Mon 2008-10-20 09:58:51: Accepting SMTP connection from [93.154.110.212:55317] Mon 2008-10-20 09:58:51: --> 220-NoSpam.com ESMTP MDaemon 192.0.0; Mon, 20 Oct 2008 09:58:51 -0500 Mon 2008-10-20 09:58:51: --> 220-Unauthorized relay prohibited. Mon 2008-10-20 09:58:51: --> 220 All transactions and IP addresses are logged. Mon 2008-10-20 09:58:51: <-- HELO mzmail212.bigrewards.com Mon 2008-10-20 09:58:51: Performing IP lookup (mzmail212.bigrewards.com) Mon 2008-10-20 09:58:51: * D=mzmail212.bigrewards.com TTL=(60) A=[93.154.110.212] Mon 2008-10-20 09:58:51: ---- End IP lookup results Mon 2008-10-20 09:58:51: --> 250 NoSpam.com Hello mzmail212.bigrewards.com, pleased to meet you Mon 2008-10-20 09:58:59: <-- MAIL FROM: <[EMAIL PROTECTED]> Mon 2008-10-20 09:58:59: Performing SPF lookup (schoolboypike.net / 93.154.110.212) Mon 2008-10-20 09:59:00: * Policy: v=spf1 ip4:93.154.100.0/22 ip4:93.154.104.0/21 ip4:93.154.112.0/21 ?all Mon 2008-10-20 09:59:00: * Evaluating ip4:93.154.100.0/22: no match Mon 2008-10-20 09:59:00: * Evaluating ip4:93.154.104.0/21: match Mon 2008-10-20 09:59:00: * Result: pass Mon 2008-10-20 09:59:00: ---- End SPF results Mon 2008-10-20 09:59:00: --> 250 <[EMAIL PROTECTED]>, Sender ok Mon 2008-10-20 09:59:00: <-- RCPT TO: <[EMAIL PROTECTED]> Mon 2008-10-20 09:59:00: Performing DNS-BL lookup (93.154.110.212 - connecting IP) Mon 2008-10-20 09:59:20: * opm.blitzed.org - timed out (10 second wait) Mon 2008-10-20 09:59:21: * bl.spamcop.net - passed Mon 2008-10-20 09:59:21: * zen.spamhaus.org - passed Mon 2008-10-20 09:59:21: ---- End DNS-BL results Mon 2008-10-20 09:59:21: --> 250 <[EMAIL PROTECTED]>, Recipient ok Mon 2008-10-20 09:59:22: <-- DATA Mon 2008-10-20 09:59:22: Creating temp file (SMTP): c:\mdaemon\temp \18\md50000000004.tmp Mon 2008-10-20 09:59:22: --> 354 Enter mail, end with <CRLF>.<CRLF> Mon 2008-10-20 10:00:24: Message size: 3959 bytes Mon 2008-10-20 10:00:24: Performing VBR certification (Domain: schoolboypike.net, Auth: SPF) Mon 2008-10-20 10:00:24: * File: c:\mdaemon\temp\18\md50000000004.tmp Mon 2008-10-20 10:00:24: * Message-ID: <[EMAIL PROTECTED]> Mon 2008-10-20 10:00:24: * Certifier (trusted): vbr.emailcertification.org ... Mon 2008-10-20 10:00:24: * Querying: schoolboypike.net._vouch.vbr.emailcertification.org ... Mon 2008-10-20 10:00:25: * Certifier does not recognize that domain Mon 2008-10-20 10:00:25: * Certification result: message not certified Mon 2008-10-20 10:00:25: ---- End VBR results Mon 2008-10-20 10:00:25: Performing DKIM lookup Mon 2008-10-20 10:00:25: * File: c:\mdaemon\temp\18\md50000000004.tmp Mon 2008-10-20 10:00:25: * Message-ID: [EMAIL PROTECTED] Mon 2008-10-20 10:00:25: * Result: neutral Mon 2008-10-20 10:00:25: ---- End DKIM results Mon 2008-10-20 10:00:25: Performing DomainKeys lookup (Sender: [EMAIL PROTECTED]) Mon 2008-10-20 10:00:25: * File: c:\mdaemon\temp\18\md50000000004.tmp Mon 2008-10-20 10:00:25: * Message-ID: [EMAIL PROTECTED] Mon 2008-10-20 10:00:25: * Signature (1): a=rsa-sha1; q=dns; c=nofws; s=default; d=schoolboypike.net; b=<not logged> Mon 2008-10-20 10:00:25: * Querying: default._domainkey.schoolboypike.net ... Mon 2008-10-20 10:00:26: * Key record: k=rsa; t=y; p=<not logged> Mon 2008-10-20 10:00:26: * Verification result: [0] good Mon 2008-10-20 10:00:26: * Result: pass Mon 2008-10-20 10:00:26: ---- End DomainKeys results Mon 2008-10-20 10:00:26: Performing VBR certification (Domain: schoolboypike.net, Auth: DomainKeys) Mon 2008-10-20 10:00:26: * File: c:\mdaemon\temp\18\md50000000004.tmp Mon 2008-10-20 10:00:26: * Message-ID: [EMAIL PROTECTED] Mon 2008-10-20 10:00:26: * Certifier (trusted): vbr.emailcertification.org ... Mon 2008-10-20 10:00:26: * Querying: schoolboypike.net._vouch.vbr.emailcertification.org ... Mon 2008-10-20 10:00:26: * Certifier does not recognize that domain Mon 2008-10-20 10:00:26: * Certification result: message not certified Mon 2008-10-20 10:00:26: ---- End VBR results Mon 2008-10-20 10:00:32: Socket error sending response to DATA Mon 2008-10-20 10:00:32: * Winsock Error 10054 Connection was reset by the other side! Mon 2008-10-20 10:00:32: SMTP session terminated (Bytes in/out: 4087/368) Mon 2008-10-20 10:00:30: ---------- Mon 2008-10-20 10:00:31: Session 2740; child 3; thread 3400 Mon 2008-10-20 10:00:30: Accepting SMTP connection from [192.168.1.1:2350] Mon 2008-10-20 10:00:30: --> 220-NoSpam.com ESMTP MDaemon 192.0.0; Mon, 20 Oct 2008 10:00:30 -0500 Mon 2008-10-20 10:00:30: --> 220-Unauthorized relay prohibited. Mon 2008-10-20 10:00:30: --> 220 All transactions and IP addresses are logged. Mon 2008-10-20 10:00:31: <-- HELO 192.168.1.1 Mon 2008-10-20 10:00:31: --> 250 NoSpam.com Hello 192.168.1.1, pleased to meet you Mon 2008-10-20 10:00:31: <-- MAIL FROM:<[EMAIL PROTECTED]> Mon 2008-10-20 10:00:31: --> 250 <[EMAIL PROTECTED]>, Sender ok Mon 2008-10-20 10:00:31: <-- RCPT TO:<[EMAIL PROTECTED]> Mon 2008-10-20 10:00:31: --> 250 <[EMAIL PROTECTED]>, Recipient ok Mon 2008-10-20 10:00:31: <-- DATA Mon 2008-10-20 10:00:31: Creating temp file (SMTP): c:\mdaemon\temp \22\md50000000004.tmp Mon 2008-10-20 10:00:31: --> 354 Enter mail, end with <CRLF>.<CRLF> Mon 2008-10-20 10:00:31: Message size: 7890 bytes Mon 2008-10-20 10:00:31: Socket error sending response to DATA Mon 2008-10-20 10:00:31: * Winsock Error 10054 Connection was reset by the other side! Mon 2008-10-20 10:00:31: SMTP session terminated (Bytes in/out: 7983/335) Mon 2008-10-20 10:00:32: ---------- Mon 2008-10-20 10:04:11: Session 2810; child 1; thread 3204 Mon 2008-10-20 10:04:09: Accepting SMTP connection from [192.168.1.97:2073] Mon 2008-10-20 10:04:09: --> 220-NoSpam.com ESMTP MDaemon 192.0.0; Mon, 20 Oct 2008 10:04:09 -0500 Mon 2008-10-20 10:04:09: --> 220-Unauthorized relay prohibited. Mon 2008-10-20 10:04:09: --> 220 All transactions and IP addresses are logged. Mon 2008-10-20 10:04:09: <-- EHLO unit1 Mon 2008-10-20 10:04:09: --> 250-NoSpam.com Hello unit1, pleased to meet you Mon 2008-10-20 10:04:09: --> 250-ETRN Mon 2008-10-20 10:04:09: --> 250-AUTH=LOGIN Mon 2008-10-20 10:04:09: --> 250-AUTH LOGIN CRAM-MD5 Mon 2008-10-20 10:04:09: --> 250-8BITMIME Mon 2008-10-20 10:04:09: --> 250 SIZE 0 Mon 2008-10-20 10:04:09: <-- MAIL FROM: <[EMAIL PROTECTED]> Mon 2008-10-20 10:04:09: --> 250 <[EMAIL PROTECTED]>, Sender ok Mon 2008-10-20 10:04:09: <-- RCPT TO: <[EMAIL PROTECTED]> Mon 2008-10-20 10:04:09: --> 250 <[EMAIL PROTECTED]>, Recipient ok Mon 2008-10-20 10:04:09: <-- DATA Mon 2008-10-20 10:04:09: Creating temp file (SMTP): c:\mdaemon\temp \23\md50000000004.tmp Mon 2008-10-20 10:04:09: --> 354 Enter mail, end with <CRLF>.<CRLF> Mon 2008-10-20 10:04:09: Message size: 4592 bytes Mon 2008-10-20 10:04:09: Message creation successful: c:\mdaemon \inbound\23\md50000019885.msg Mon 2008-10-20 10:04:09: --> 250 Ok, message saved <Message-ID: [EMAIL PROTECTED]> Mon 2008-10-20 10:04:11: <-- QUIT Mon 2008-10-20 10:04:11: --> 221 See ya in cyberspace Mon 2008-10-20 10:04:11: SMTP session successful (Bytes in/out: 4694/522) Mon 2008-10-20 10:04:11: ---------- Mon 2008-10-20 10:03:52: Session 2803; child 1; thread 3812 Mon 2008-10-20 10:03:47: Accepting SMTP connection from [122.231.69.215:4776] Mon 2008-10-20 10:03:47: --> 220-NoSpam.com ESMTP MDaemon 192.0.0; Mon, 20 Oct 2008 10:03:47 -0500 Mon 2008-10-20 10:03:47: --> 220-Unauthorized relay prohibited. Mon 2008-10-20 10:03:47: --> 220 All transactions and IP addresses are logged. Mon 2008-10-20 10:03:48: <-- EHLO legend-964c81e9 Mon 2008-10-20 10:03:48: Performing IP lookup (legend-964c81e9) Mon 2008-10-20 10:03:49: * Error: * Name server reports domain name unknown Mon 2008-10-20 10:03:49: ---- End IP lookup results Mon 2008-10-20 10:03:49: --> 250-NoSpam.com Hello legend-964c81e9, pleased to meet you Mon 2008-10-20 10:03:49: --> 250-ETRN Mon 2008-10-20 10:03:49: --> 250-AUTH=LOGIN Mon 2008-10-20 10:03:49: --> 250-AUTH LOGIN CRAM-MD5 Mon 2008-10-20 10:03:49: --> 250-8BITMIME Mon 2008-10-20 10:03:49: --> 250 SIZE 0 Mon 2008-10-20 10:03:50: <-- MAIL FROM:<[EMAIL PROTECTED]> Mon 2008-10-20 10:03:50: Performing SPF lookup (timenow.com / 122.231.69.215) Mon 2008-10-20 10:03:50: * Result: none; no SPF record in DNS Mon 2008-10-20 10:03:50: ---- End SPF results Mon 2008-10-20 10:03:50: --> 250 <[EMAIL PROTECTED]>, Sender ok Mon 2008-10-20 10:03:51: <-- RCPT TO: <[EMAIL PROTECTED]> Mon 2008-10-20 10:03:51: Sender attempted to deliver message to unknown address Mon 2008-10-20 10:03:51: --> 550 <[EMAIL PROTECTED]>, Recipient unknown Mon 2008-10-20 10:03:52: <-- QUIT Mon 2008-10-20 10:03:52: --> 221 See ya in cyberspace Mon 2008-10-20 10:03:52: SMTP session terminated (Bytes in/out: 105/417) Mon 2008-10-20 10:03:52: ---------- Thanks again for all your help! On Oct 24, 11:45 am, Andrew Long <[EMAIL PROTECTED]> wrote: > On 24 Oct 2008, at 15:19, SysAdm wrote: > > > > > Good morning Andrew, > > I should have done this before. Below is a clipping from the mail > > logfile containing one of the sections I'm trying to search/highlight > > for. The hyphens are on seperate lines and kind of delineate that > > particular email transaction. > ><snip/> > > Sorry I didn't post this before. So I would like to be able to search > > for and highlight the portion starting at "timesheet" (perhaps "FROM: > > timesheet"?) through a potentially varying number of lines to the line > > with "Winsock Error"; then be able to hit "n" for next to go to the > > next occurrence of this Winsock error from timesheet. Hope this makes > > it more clear. > > Can I just clarify... you are ONLY interested in FAILED emails, ones > where there is a winsock error message, right? That makes it more > difficult. We have to find some way to stop matching successful emails, > otherwise it'll start highlighting on a successful mail and not stop > until it finds a failure. > > Do you have a sample of a successful mail log entry that you can post? I > think some kind of zero-length match 'dos not match here' pattern might > do the trick, but I'm not too up on those.... > > :help zero-with > > gives a couple of patterns ([EMAIL PROTECTED] for ex) but I'm not sure they'd > work. > After all, proving a negative is one of the hardest tasks. > > REgards, Andy > -- > Andrew Long > andrew dot long at mac dot com --~--~---------~--~----~------------~-------~--~----~ You received this message from the "vim_use" maillist. For more information, visit http://www.vim.org/maillist.php -~----------~----~----~----~------~----~------~--~---
