Can you cut part of you log file and send to the list? I am able to detect in a single line when I find "NOQUEUE" in log.
Regards, Newton Pasqualini Filho newtonpasqual...@gmail.com Em 13/06/2013, às 18:34, Rob Tanner <rtan...@linfield.edu> escreveu: > Hi, > > I'm trying to come up with mechanisms to catch compromised accounts sending > SPAM. Since spammers don't necessarily have all good addresses a large > number of their SPAM messages bounce with 550 errors (mailbox unavailable or > doesn't even exist). I would like to monitor men logs and catch that > pattern. The problem is that the log entry that includes the 550 error only > shows where the message was intended to go and not where it came from. > That's found on another log entry line. Is there anyway to tweak the logging > mechanism so both bits of data appear on the same log line? > > Thanks. > > > Rob Tanner > UNIX Services Manager > Linfield College, McMinnville Oregon > > ITS will never ask you for your password. Please don’t share yours with > anyone! >