ClearSwift
ArchivedThe Clearswift application normalizes Clearswift SEG events and enables you to analyze Clearswift SEG data using pre-set dashboard views. You can further customize the dashboard and searches to perform in-depth analysis.
Release Details
Package Details
- Dashboard Package
- LP_Clearswift SEG: Top 10 Senders and Recipients
- Normalization Packages
- LP_Clearswift SEG
- LP_Clearswift SWG
- LP_Clearswift SEG Generic
- Search Templates
- LP_Inbound Mail Activities
- LP_Outbound Mail Activities
Enhancement
Installation
Follow these steps to install the Clearswift v5.0.0 plugin:
- Download the Clearswift package from the Download section above.
- Add the required Clearswift server as a device in LogPoint.
- Create a collection policy with the Syslog collector and appropriate processing policy.
- Assign the policy to the device.
- Add the dashboard.
Log Formats
Expected Log Format
Inbound Mail Sender Log
Log Samples
<22>1 2015-10-29T11:40:52Z p1mail.abc.xyzn.com mail - - - sm-inbound[21101]: t9TBeqNh021101: <-- MAIL FROM:<abc@xyz.com> SIZE=11966
Aug 17 11:29:56 sm-inbound[32401]: t7H9Tta8032401: <-- MAIL From:<abc@xyz.com> SIZE=5867 BODY=8BITMIME
Expected Log Format
Inbound Mail Recipient Log
Log Sample
<22>1 2015-10-29T11:40:52Z p1mail.abc.xyzn.com mail - - - sm-inbound[21101]: t9TBeqMh021101: <-- RCPT TO:<abc@xyz.com> ORCPT=rfc822;abc@lp.com
Aug 17 11:30:10 sm-inbound[32401]: t7H9Tta8032401: <-- RCPT To:<abc@xyz.com> ORCPT=rfc822;abc@xyz.com
Expected Log Format
Outbound Mail Sender Log
Log Samples
<22>1 2015-10-29T11:40:07Z p1mail.abc.xyzn.com mail - - - sm-outbound[17545]: t9TBe2kJ017431: >>> MAIL From:<g-9005764543-6096-751094688-1446118796472@service.xyz.com> SIZE=90663
Aug 17 10:42:06 sm-outbound[27319]: t7H8fjLq026622: >>> MAIL From:<138440.349835194@xyz.com> SIZE=20790
Expected Log Format
Outbound Mail Recipient Log
Log Samples
<22>1 2015-10-29T11:40:07Z p1mail.abc.xyzn.com mail - - - sm-outbound[17545]: t9TBe2kJ017431: >>> RCPT To:<user@xyzn.com>
Aug 17 10:42:06 sm-outbound[27319]: t7H8fjLq026622: >>> RCPT To:<abc@xyz.com>
To export data to LogPoint use Syslog collector on port 514 on the LogPoint server.
Support
If you have any questions or require assistance, create a support ticket.
Comments
Article is closed for comments.
hi, dashboard isnt working because there are labels defined, but there is no label-package and the logs are not labeled. what i have to do?