42
Chapter 3 Tracking Email Messages
Understanding Tracking Query Setup
3-6
Cisco IronPort AsyncOS 7.5 for Email Daily Management Guide
OL-25138-01
•
Subject: Select “Begins With,” “Is,” “Contains,” or “Is Empty,” and enter a
text string to search for in the message subject line.
Note
International character sets are not supported in the subject header.
•
Dates and Times: Specify a date and time range for the query. If you do not
specify a date, the query returns data for all dates. If you specify a time range
only, the query returns data for that time range across all available dates.
Dates and times are converted to GMT format when they are stored in the
database. When you view dates and times on an appliance, they are converted
to the local time of the appliance.
Messages appear in the results only after they have been logged. Depending
on the size of logs and the frequency of polling, there could be a small gap
between the time when an email was sent and when it actually appears in
tracking and reporting results. See Chapter 5, “Logging” for more details.
•
Message Event: Select the events to track. Options are “Virus Positive,”
“Spam Positive,” “Suspect Spam,” “Delivered,” “Hard Bounced,” “Soft
Bounced,” “Currently in Outbreak Quarantine,” “DLP Violations,” and
“Quarantined as Spam.” Unlike most conditions that you add to a tracking
query, events are added with an “OR” operator. Selecting multiple events
expands the search.
If you select “DLP Violations,” AsyncOS displays additional DLP-related
options are displayed. Options are the DLP policy that the messages violated
and the severity of the violation (“Critical,” “High,” “Medium,” and “Low”).
By default, only administrators can view matched content when running
searches for DLP violations. To allow other users, including delegated
administrators, to view this content, enable the DLP Tracking Privileges
through the System Administration > Users page. See Disabling Access to
Sensitive Information in Message Tracking, page 8-25 for more information.
•
Message-ID Header and MID: Enter a text string for the “Message-ID:”
header, the IronPort message ID (MID), or both.
•
Attachment Name: Select Begins With, Is, or Contains, and enter an ASCII
or Unicode text string for one Attachment Name to find.