Mercury Suggestions
Log Search

In some other mailserver software there are functionalities for searching the logs. This is very handy when tracking down, what has happened to a particular message.
Now with the logs being in different log-files depending on module a trace type of search is nearly impossible without first joining the log files smartly.

Since the start of this community I am now receiving more than a 100 false messages based on honeypot catches. But thanks to running another mailserver than mercury for the web-based outbound I have the possibility to track the returning messages and their cause. Well, since I want to omit having a second mailserver software and only rely on Mercury, the search and examine possibility of the Logs would be appreciated. Below is an example log, showing a honeypot trace to cybernirvana.com.

Detail Report


2007-maj-24 14:12:05  Action: Message Accepted  Client: 194.63.129.54  From: ILIJAGunko@CYBERNIRVANA.COM  
To: cleanserdeftest@ihpu.se  Subject: Kapitalanlage.  Size: 894  
SMTP ID: M2007052414115929535  Connection ID: 207297  

2007-maj-24 14:12:17  Action: Message Delivery Attempt Failed  Client: 194.63.129.54  From: ILIJAGunko@CYBERNIRVANA.COM  
To: cleanserdeftest@ihpu.se  Subject: Kapitalanlage.  SMTP ID: M2007052414115929535  
Connection ID: 207301  Last Command: RCPT To  Last Response: 550 Address '<cleanserdeftest@ihpu.se>' not known here.  

2007-maj-24 14:12:17  Action: Message Generated  From: Symantec_Mail_Security_for_SMTP@workorder.se  To: ILIJAGunko@CYBERNIRVANA.COM  
Size: 1839  SMTP ID: M2007052414121729538  Reference SMTP ID: M2007052414115929535  
Info: Automatically generated bounce message.  

2007-maj-24 14:12:17  Action: Message Bounced  Client: 194.63.129.54  From: ILIJAGunko@CYBERNIRVANA.COM  
To: cleanserdeftest@ihpu.se  Subject: Kapitalanlage.  SMTP ID: M2007052414115929535  
Info: Mailbox unknown or not accepting mail.  Info2: 550 Address '<cleanserdeftest@ihpu.se>' not known here.   

2007-maj-24 14:12:17  Action: Message Processing Completed  Client: 194.63.129.54  From: ILIJAGunko@CYBERNIRVANA.COM  
To: cleanserdeftest@ihpu.se  Subject: Kapitalanlage.  SMTP ID: M2007052414115929535  

2007-maj-24 14:12:26  Action: Message Delivered  Server: mail-fwd.g14.rapidsite.net:25  From: Symantec_Mail_Security_for_SMTP@workorder.se  
To: ILIJAGunko@CYBERNIRVANA.COM  SMTP ID: M2007052414121729538  Connection ID: 207303  
Last Response: 250 0-0661568745 Message accepted for delivery  

2007-maj-24 14:12:26  Action: Message Processing Completed  From: Symantec_Mail_Security_for_SMTP@workorder.se  To: ILIJAGunko@CYBERNIRVANA.COM  
SMTP ID: M2007052414121729538  


7 matching records found.

&lt;P&gt;In some other mailserver software there are functionalities for searching the logs. This is very handy when tracking down, what has happened to a particular message. Now with the logs being in different log-files depending on module a trace type of search is nearly impossible without first joining the log files smartly.&lt;/P&gt; &lt;P&gt;Since the start of this community I am now receiving more than a 100 false messages based on honeypot catches. But thanks to running another mailserver than mercury for the web-based outbound I have the possibility to track the returning messages and their cause. Well, since I want to omit having a second mailserver software and only rely on Mercury, the search and examine possibility of the Logs would be appreciated. Below is an example log, showing a honeypot trace to cybernirvana.com.&lt;/P&gt; &lt;CENTER&gt;&lt;FONT face=&quot;Arial, Helvetica&quot; size=3&gt;&lt;B&gt;Detail Report&lt;/FONT&gt;&lt;/B&gt; &lt;HR width=&quot;75%&quot;&gt; &lt;/CENTER&gt; &lt;P&gt;&lt;FONT face=&quot;Arial, Helvetica&quot; size=-1&gt;2007-maj-24 14:12:05&amp;nbsp;&amp;nbsp;Action: &lt;FONT color=#008800&gt;Message Accepted&lt;/FONT&gt;&amp;nbsp;&amp;nbsp;Client: &lt;FONT color=#008800&gt;194.63.129.54&lt;/FONT&gt;&amp;nbsp;&amp;nbsp;From: &lt;FONT color=#008800&gt;ILIJAGunko@CYBERNIRVANA.COM&lt;/FONT&gt;&amp;nbsp;&amp;nbsp; To: &lt;FONT color=#008800&gt;cleanserdeftest@ihpu.se&lt;/FONT&gt;&amp;nbsp;&amp;nbsp;Subject: &lt;FONT color=#008800&gt;Kapitalanlage.&lt;/FONT&gt;&amp;nbsp;&amp;nbsp;Size: &lt;FONT color=#008800&gt;894&lt;/FONT&gt;&amp;nbsp;&amp;nbsp; SMTP ID: &lt;FONT color=#008800&gt;M2007052414115929535&lt;/FONT&gt;&amp;nbsp;&amp;nbsp;Connection ID: &lt;FONT color=#008800&gt;207297&lt;/FONT&gt;&amp;nbsp;&amp;nbsp; 2007-maj-24 14:12:17&amp;nbsp;&amp;nbsp;Action: &lt;FONT color=#ff8429&gt;Message Delivery Attempt Failed&lt;/FONT&gt;&amp;nbsp;&amp;nbsp;Client: &lt;FONT color=#008800&gt;194.63.129.54&lt;/FONT&gt;&amp;nbsp;&amp;nbsp;From: &lt;FONT color=#008800&gt;ILIJAGunko@CYBERNIRVANA.COM&lt;/FONT&gt;&amp;nbsp;&amp;nbsp; To: &lt;FONT color=#008800&gt;cleanserdeftest@ihpu.se&lt;/FONT&gt;&amp;nbsp;&amp;nbsp;Subject: &lt;FONT color=#008800&gt;Kapitalanlage.&lt;/FONT&gt;&amp;nbsp;&amp;nbsp;SMTP ID: &lt;FONT color=#008800&gt;M2007052414115929535&lt;/FONT&gt;&amp;nbsp;&amp;nbsp; Connection ID: &lt;FONT color=#008800&gt;207301&lt;/FONT&gt;&amp;nbsp;&amp;nbsp;Last Command: &lt;FONT color=#008800&gt;RCPT To&lt;/FONT&gt;&amp;nbsp;&amp;nbsp;Last Response: &lt;FONT color=#008800&gt;550 Address &#039;&amp;lt;cleanserdeftest@ihpu.se&amp;gt;&#039; not known here.&lt;/FONT&gt;&amp;nbsp;&amp;nbsp; 2007-maj-24 14:12:17&amp;nbsp;&amp;nbsp;Action: &lt;FONT color=#ff8429&gt;Message Generated&lt;/FONT&gt;&amp;nbsp;&amp;nbsp;From: &lt;FONT color=#008800&gt;Symantec_Mail_Security_for_SMTP@workorder.se&lt;/FONT&gt;&amp;nbsp;&amp;nbsp;To: &lt;FONT color=#008800&gt;ILIJAGunko@CYBERNIRVANA.COM&lt;/FONT&gt;&amp;nbsp;&amp;nbsp; Size: &lt;FONT color=#008800&gt;1839&lt;/FONT&gt;&amp;nbsp;&amp;nbsp;SMTP ID: &lt;FONT color=#008800&gt;M2007052414121729538&lt;/FONT&gt;&amp;nbsp;&amp;nbsp;Reference SMTP ID: &lt;FONT color=#008800&gt;M2007052414115929535&lt;/FONT&gt;&amp;nbsp;&amp;nbsp; Info: &lt;FONT color=#008800&gt;Automatically generated bounce message.&lt;/FONT&gt;&amp;nbsp;&amp;nbsp; 2007-maj-24 14:12:17&amp;nbsp;&amp;nbsp;Action: &lt;FONT color=#ff8429&gt;Message Bounced&lt;/FONT&gt;&amp;nbsp;&amp;nbsp;Client: &lt;FONT color=#008800&gt;194.63.129.54&lt;/FONT&gt;&amp;nbsp;&amp;nbsp;From: &lt;FONT color=#008800&gt;ILIJAGunko@CYBERNIRVANA.COM&lt;/FONT&gt;&amp;nbsp;&amp;nbsp; To: &lt;FONT color=#008800&gt;cleanserdeftest@ihpu.se&lt;/FONT&gt;&amp;nbsp;&amp;nbsp;Subject: &lt;FONT color=#008800&gt;Kapitalanlage.&lt;/FONT&gt;&amp;nbsp;&amp;nbsp;SMTP ID: &lt;FONT color=#008800&gt;M2007052414115929535&lt;/FONT&gt;&amp;nbsp;&amp;nbsp; Info: &lt;FONT color=#008800&gt;Mailbox unknown or not accepting mail.&lt;/FONT&gt;&amp;nbsp;&amp;nbsp;Info2: &lt;FONT color=#008800&gt;550 Address &#039;&amp;lt;cleanserdeftest@ihpu.se&amp;gt;&#039; not known here. &lt;/FONT&gt;&amp;nbsp;&amp;nbsp; 2007-maj-24 14:12:17&amp;nbsp;&amp;nbsp;Action: &lt;FONT color=#008800&gt;Message Processing Completed&lt;/FONT&gt;&amp;nbsp;&amp;nbsp;Client: &lt;FONT color=#008800&gt;194.63.129.54&lt;/FONT&gt;&amp;nbsp;&amp;nbsp;From: &lt;FONT color=#008800&gt;ILIJAGunko@CYBERNIRVANA.COM&lt;/FONT&gt;&amp;nbsp;&amp;nbsp; To: &lt;FONT color=#008800&gt;cleanserdeftest@ihpu.se&lt;/FONT&gt;&amp;nbsp;&amp;nbsp;Subject: &lt;FONT color=#008800&gt;Kapitalanlage.&lt;/FONT&gt;&amp;nbsp;&amp;nbsp;SMTP ID: &lt;FONT color=#008800&gt;M2007052414115929535&lt;/FONT&gt;&amp;nbsp;&amp;nbsp; 2007-maj-24 14:12:26&amp;nbsp;&amp;nbsp;Action: &lt;FONT color=#008800&gt;Message Delivered&lt;/FONT&gt;&amp;nbsp;&amp;nbsp;Server: &lt;FONT color=#008800&gt;mail-fwd.g14.rapidsite.net:25&lt;/FONT&gt;&amp;nbsp;&amp;nbsp;From: &lt;FONT color=#008800&gt;Symantec_Mail_Security_for_SMTP@workorder.se&lt;/FONT&gt;&amp;nbsp;&amp;nbsp; To: &lt;FONT color=#008800&gt;ILIJAGunko@CYBERNIRVANA.COM&lt;/FONT&gt;&amp;nbsp;&amp;nbsp;SMTP ID: &lt;FONT color=#008800&gt;M2007052414121729538&lt;/FONT&gt;&amp;nbsp;&amp;nbsp;Connection ID: &lt;FONT color=#008800&gt;207303&lt;/FONT&gt;&amp;nbsp;&amp;nbsp; Last Response: &lt;FONT color=#008800&gt;250 0-0661568745 Message accepted for delivery&lt;/FONT&gt;&amp;nbsp;&amp;nbsp; 2007-maj-24 14:12:26&amp;nbsp;&amp;nbsp;Action: &lt;FONT color=#008800&gt;Message Processing Completed&lt;/FONT&gt;&amp;nbsp;&amp;nbsp;From: &lt;FONT color=#008800&gt;Symantec_Mail_Security_for_SMTP@workorder.se&lt;/FONT&gt;&amp;nbsp;&amp;nbsp;To: &lt;FONT color=#008800&gt;ILIJAGunko@CYBERNIRVANA.COM&lt;/FONT&gt;&amp;nbsp;&amp;nbsp; SMTP ID: &lt;FONT color=#008800&gt;M2007052414121729538&lt;/FONT&gt;&amp;nbsp;&amp;nbsp; &lt;/TABLE&gt;&lt;/FONT&gt; &lt;I&gt;7 matching records found.&lt;/I&gt;&lt;/P&gt;

Mercury's log files are all plain text and can be easily searched using any grep or similar utility. They were specifically designed this way for exactly this reason.

Cheers!

-- David --

&lt;p&gt;Mercury&#039;s log files are all plain text and can be easily searched using any grep or similar utility. They were specifically designed this way for exactly this reason. Cheers! -- David -- &lt;/p&gt;

I bet not many know what grep is these days....

Anyhow - does anyone have any good pointers to a web-based grep util?

&lt;P&gt;I bet not many know what grep is these days....&lt;/P&gt; &lt;P&gt;Anyhow - does anyone have any good pointers to a web-based grep util?&lt;/P&gt;

This is the one I use frequently, it's under dos though:

c:\>grep
Name:     grep - regular expression search through files
Usage:    grep [ -vclins? ] <pattern> file1 ...
Version:  3.0 for PCs with DOS 2.1 and higher
          (C) Copyright Peter Stephen Heitman 1986  --  All Rights Reserved
          Distributed with the PiCnix Package (tm) by Peter Stephen Heitman
          Regular expression pattern matching algorithm:
             Copyright (c) 1986 by University of Toronto.
             Written by Henry Spencer.  Not derived from licensed software.

I doubt this little util even know's what "the web" is[:D]

 

&lt;p&gt;This is the one I use frequently, it&#039;s under dos though:&lt;/p&gt;&lt;p&gt;c:\&amp;gt;grep Name:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; grep - regular expression search through files Usage:&amp;nbsp;&amp;nbsp;&amp;nbsp; grep [ -vclins? ] &amp;lt;pattern&amp;gt; file1 ... Version:&amp;nbsp; 3.0 for PCs with DOS 2.1 and higher &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (C) Copyright Peter Stephen Heitman 1986&amp;nbsp; --&amp;nbsp; All Rights Reserved &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Distributed with the PiCnix Package (tm) by Peter Stephen Heitman &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Regular expression pattern matching algorithm: &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Copyright (c) 1986 by University of Toronto. &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Written by Henry Spencer.&amp;nbsp; Not derived from licensed software.&lt;/p&gt;&lt;p&gt;I doubt this little util even know&#039;s what &quot;the web&quot; is[:D]&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;

-- Han van den Bogaerde - support@vandenbogaerde.net Member of Pegasus Mail Support Group. My own Pegasus Mail related web information: http://www.vandenbogaerde.net/pegasusmail/

I use a spreadsheet (Excel - but OO works too) to import all my text log files.

Each log file gets its own tab and can refresh as required (manual or at set intervals).

This gives me the ability to have  data analysis columns next to the imported log and to filter as I want.

After trying quite a few log viewers etc. (none would do it the way I want) I have found this the fastest way of doing log traces. 

&lt;p&gt;I use a spreadsheet (Excel - but OO works too) to import all my text log files.&lt;/p&gt;&lt;p&gt;Each log file gets its own tab and can refresh as required (manual or at set intervals).&lt;/p&gt;&lt;p&gt;This gives me the ability to have&amp;nbsp; data analysis columns next to the imported log and to filter as I want.&lt;/p&gt;&lt;p&gt;After trying quite a few log viewers etc. (none would do it the way I want) I have found this the fastest way of doing log traces.&amp;nbsp;&lt;/p&gt;

It can be handy to see what is happening live in the logs.

For Windows I use BareTail: http://www.baremetalsoft.com/baretail/ 

 And for a windows based GUI Grep BareGrep: http://www.baremetalsoft.com/baregrep/index.php
 

&lt;p&gt;It can be handy to see what is happening live in the logs.&lt;/p&gt;&lt;p&gt;For Windows I use BareTail: &lt;a href=&quot;http://www.baremetalsoft.com/baretail/%20&quot; title=&quot;http://www.baremetalsoft.com/baretail/ &quot; mce_href=&quot;http://www.baremetalsoft.com/baretail/ &quot;&gt;http://www.baremetalsoft.com/baretail/&amp;nbsp;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;And for a windows based GUI Grep BareGrep: &lt;a href=&quot;http://www.baremetalsoft.com/baregrep/index.php&quot; title=&quot;http://www.baremetalsoft.com/baregrep/index.php&quot; mce_href=&quot;http://www.baremetalsoft.com/baregrep/index.php&quot;&gt;http://www.baremetalsoft.com/baregrep/index.php&lt;/a&gt; &amp;nbsp;&lt;/p&gt;
live preview
enter atleast 10 characters
WARNING: You mentioned %MENTIONS%, but they cannot see this message and will not be notified
Saving...
Saved
With selected deselect posts show selected posts
All posts under this topic will be deleted ?
Pending draft ... Click to resume editing
Discard draft