Archive

why mimecast held logging has changed?

Explorer

Hi,

Earlier we used to receive mimecast held messages in below format:

date=2018-01-15T02:38:00+0000| mcType=mimecastHeld|to=recipient address|from=sender address|reason="Message Hold Applied - Spam Signature policy"|subject="subject"

But since 15th jan, 2018 we are getting them in below format,
datetime=2018-01-01T18:30:20+0000|aCode=|acc=|Hld=Spm|AttSize=0|Act=Hld|AttCnt=0|AttNames=|MsgSize=19484|MsgId=|mcType=process

Now there is no way we can check information of any held message in Splunk?

Any suggestions will help.

Thanks in advance

0 Karma
1 Solution

Path Finder

Hi there - the information you used to see used a legacy API. To find more information about a held message in v2 you can take the MsgId value from one of these log lines:

datetime=2018-01-01T18:30:20+0000|aCode=|acc=|Hld=Spm|AttSize=0|Act=Hld|AttCnt=0|AttNames=|MsgSize=19484|MsgId=|mcType=process

and search for mcType = receipt MsgId = "VALUE FROM PREVIOUS LINE"

I hope this helps.

View solution in original post

0 Karma

Path Finder

Hi there - the information you used to see used a legacy API. To find more information about a held message in v2 you can take the MsgId value from one of these log lines:

datetime=2018-01-01T18:30:20+0000|aCode=|acc=|Hld=Spm|AttSize=0|Act=Hld|AttCnt=0|AttNames=|MsgSize=19484|MsgId=|mcType=process

and search for mcType = receipt MsgId = "VALUE FROM PREVIOUS LINE"

I hope this helps.

View solution in original post

0 Karma