Hi,
Earlier we used to receive mimecast held messages in below format:
date=2018-01-15T02:38:00+0000| mcType=mimecastHeld|to=recipient address|from=sender address|reason="Message Hold Applied - Spam Signature policy"|subject="subject"
But since 15th jan, 2018 we are getting them in below format,
datetime=2018-01-01T18:30:20+0000|aCode=|acc=|Hld=Spm|AttSize=0|Act=Hld|AttCnt=0|AttNames=|MsgSize=19484|MsgId=|mcType=process
Now there is no way we can check information of any held message in Splunk?
Any suggestions will help.
Thanks in advance
Hi there - the information you used to see used a legacy API. To find more information about a held message in v2 you can take the MsgId value from one of these log lines:
datetime=2018-01-01T18:30:20+0000|aCode=|acc=|Hld=Spm|AttSize=0|Act=Hld|AttCnt=0|AttNames=|MsgSize=19484|MsgId=|mcType=process
and search for mcType = receipt MsgId = "VALUE FROM PREVIOUS LINE"
I hope this helps.
Hi there - the information you used to see used a legacy API. To find more information about a held message in v2 you can take the MsgId value from one of these log lines:
datetime=2018-01-01T18:30:20+0000|aCode=|acc=|Hld=Spm|AttSize=0|Act=Hld|AttCnt=0|AttNames=|MsgSize=19484|MsgId=|mcType=process
and search for mcType = receipt MsgId = "VALUE FROM PREVIOUS LINE"
I hope this helps.