![]() |
bmSearch
0.0.4
|
Variables | |
amavisLine = re.compile(r"(?P<date>.{6}) (?P<hour>.{8}) (.*)(amavis)\[\d+\]: \((\d+)-(\d+)\) (?P<status>.*}), .*, Message-ID: <(?P<messageid>.*)>, .*") | |
Amavis Jul 19 15:10:13 uruviel amavis[17590]: (17590-18) Blocked BANNED (.exe,. More... | |
bodyDateLine = re.compile(r"(?P<date>.{6}) (?P<hour>.{8}) (.*)(postfix/cleanup)\[(\d+)\]: (?P<queueid>.*): warning.*: bodyDate=(?P<bodyDate>.*)") | |
bodyFromLine = re.compile(r"(?P<date>.{6}) (?P<hour>.{8}) (.*)(postfix/cleanup)\[(\d+)\]: (?P<queueid>.*): warning.*: bodyFrom=(?P<bodyFrom>.*)") | |
bodySubjectLine = re.compile(r"(?P<date>.{6}) (?P<hour>.{8}) (.*)(postfix/cleanup)\[(\d+)\]: (?P<queueid>.*): warning.*: bodySubject=(?P<bodySubject>.*)") | |
cleanupLine = re.compile(r"(?P<date>.{6}) (?P<hour>.{8}) (.*)(postfix/cleanup)\[(\d+)\]: (?P<queueid>.*): message-id=(?P<messageid>.*)") | |
Get message-id on receiving message Aug 22 20:09:21 galadriel postfix/cleanup[11415]: 6C54B9E433D: message-id=20090 8222 00921 .9q4 fg64u 0wg4 swkw@ mail .mcla boss e.frMore... | |
cyrusDelivered = re.compile(r"(?P<date>.{6}) (?P<hour>.{8}) (.*)(cyrus/lmtp.*)\[(\d+)\]: Delivered: (?P<messageid>.*) to mailbox: (?P<domain>.*)\!user.(?P<user>.*)") | |
filenameLine = re.compile(r"(?P<date>.{6}) (?P<hour>.{8}) (.*)(postfix/cleanup)\[(\d+)\]: (?P<queueid>.*): warning.*: ThisFileName=(?P<filename>.*)") | |
Get filename on trace line (cf postfix "main.cf" file) Sep 5 10:16:10 galadriel postfix/cleanup[1302]: 6B1E32A87CE: warning: header Content-Type: image/png;? name="pascal.salaun_nbAtt_.png" from unknown[192.168.1.4]; \ from=frodo to= n.sa quet@ lapo ste.n etfrodo proto=ESMTP helo=<[192.168.1.4]>: ThisFileName=pascal.salaun_nbAtt_.png. n.sa quet@ lapo ste.n etMore... | |
klmsLine = re.compile(r"(?P<date>.{6}) (?P<hour>.{8}) .* KLMS: (?P<status>.*): message-id=(?P<messageid>.*): relay.* av-status=(?P<avstatus>.*), ap-status=(?P<apstatus>.*), as-status=(?P<asstatus>.*),.*") | |
KLMS Jun 8 10:30:00 toto4 KLMS: clean: message-id="D2D75237B513CA42B5E59766133F55003F60695C@ex-mbx1.siege.grouponet.com": relay-ip="212.99.25.65": action="Skipped": rules="1": size=3458: mail-from="technique@toto.com": rcpt-to="pascal.salaun@mclabosse.fr": av-status="Clean", ap-status="Clean", as-status="Clean", cf-status="NotScanned, disabled by settings". More... | |
qmgrLine = re.compile(r"(?P<date>.{6}) (?P<hour>.{8}) (.*)(postfix/qmgr)\[(\d+)\]: (?P<queueid>.*): from=<(?P<from>.*)>, size=(?P<size>\d+), nrcpt=(?P<nrcpt>\d+).*") | |
Get originator, volume and number of recip Aug 22 15:38:15 galadriel postfix/qmgr[4158]: 7E83C9E4318: from=frodo, size=1767, nrcpt=1 (queue active) n.sa quet@ lapo ste.n etMore... | |
smtpdLine = re.compile(r"(?P<date>.{6}) (?P<hour>.{8}) (.*)(postfix/smtpd)\[(\d+)\]: (?P<queueid>.*): client=(?P<server>.*)(?:(, .*)+)?") | |
Get smtpd queueid on connection Aug 22 15:38:15 galadriel postfix/smtpd[29211]: 7E83C9E4318: client=. More... | |
smtpLineDSN2 = re.compile(r"(?P<date>.{6}) (?P<hour>.{8}) (.*)(postfix/)(.*)\[(\d+)\]: (?P<queueid>.*): to=<(?P<recip>.*?)(?:>, orig_to=<(?P<orig>.*?))?>, (.*)status=sent.*") | |
Get list of destinators (dsn=2. More... | |
smtpLineDSN4 = re.compile(r"(?P<date>.{6}) (?P<hour>.{8}) (.*)(postfix/)(.*)\[(\d+)\]: (?P<queueid>.*): to=<(?P<recip>.*?)(?:>, orig_to=<(?P<orig>.*?))?>, (relay=.*)?(.*)status=deferred.*") | |
Get list of deferred destinator (dsn=4. More... | |
smtpLineDSN5 = re.compile(r"(?P<date>.{6}) (?P<hour>.{8}) (.*)(postfix/)(.*)\[(\d+)\]: (?P<queueid>.*): to=<(?P<recip>.*?)(?:>, orig_to=<(?P<orig>.*?))?>, (relay=.*)?(.*)status=bounced.*") | |
Get list of deferred destinator (dsn=5. More... | |
smtpRemoved = re.compile(r"(?P<date>.{6}) (?P<hour>.{8}) (.*)(postfix/qmgr)\[(\d+)\]: (?P<queueid>.*): removed") | |
Get smtpd queueid before disconnection (file removed from spool) Apr 30 00:07:56 uruviel postfix/qmgr[4321]: 5141E341A1B: removed. More... | |
inc.regex.amavisLine = re.compile(r"(?P<date>.{6}) (?P<hour>.{8}) (.*)(amavis)\[\d+\]: \((\d+)-(\d+)\) (?P<status>.*}), .*, Message-ID: <(?P<messageid>.*)>, .*") |
Amavis Jul 19 15:10:13 uruviel amavis[17590]: (17590-18) Blocked BANNED (.exe,.
/postinst) {BouncedOutbound,Quarantined}, LOCAL [127.0.0.1]:57722 pasca -> l.sa laun@ mcla bosse .frtechn, quarantine: R/banned-RtHNQLxoqL4r, Queue-ID: 25BBA222C2, Message-ID: ique @toto .com05ae2, mail_id: RtHNQLxoqL4r, Hits: -, size: 820289, 2193 ms 9a5f 9572e cc6d 9de27 1f11 86030 @mcl aboss e.fr
inc.regex.bodyDateLine = re.compile(r"(?P<date>.{6}) (?P<hour>.{8}) (.*)(postfix/cleanup)\[(\d+)\]: (?P<queueid>.*): warning.*: bodyDate=(?P<bodyDate>.*)") |
inc.regex.bodyFromLine = re.compile(r"(?P<date>.{6}) (?P<hour>.{8}) (.*)(postfix/cleanup)\[(\d+)\]: (?P<queueid>.*): warning.*: bodyFrom=(?P<bodyFrom>.*)") |
inc.regex.bodySubjectLine = re.compile(r"(?P<date>.{6}) (?P<hour>.{8}) (.*)(postfix/cleanup)\[(\d+)\]: (?P<queueid>.*): warning.*: bodySubject=(?P<bodySubject>.*)") |
inc.regex.cleanupLine = re.compile(r"(?P<date>.{6}) (?P<hour>.{8}) (.*)(postfix/cleanup)\[(\d+)\]: (?P<queueid>.*): message-id=(?P<messageid>.*)") |
Get message-id on receiving message Aug 22 20:09:21 galadriel postfix/cleanup[11415]: 6C54B9E433D: message-id=20090 8222 00921 .9q4 fg64u 0wg4 swkw@ mail .mcla boss e.fr
inc.regex.cyrusDelivered = re.compile(r"(?P<date>.{6}) (?P<hour>.{8}) (.*)(cyrus/lmtp.*)\[(\d+)\]: Delivered: (?P<messageid>.*) to mailbox: (?P<domain>.*)\!user.(?P<user>.*)") |
inc.regex.filenameLine = re.compile(r"(?P<date>.{6}) (?P<hour>.{8}) (.*)(postfix/cleanup)\[(\d+)\]: (?P<queueid>.*): warning.*: ThisFileName=(?P<filename>.*)") |
Get filename on trace line (cf postfix "main.cf" file) Sep 5 10:16:10 galadriel postfix/cleanup[1302]: 6B1E32A87CE: warning: header Content-Type: image/png;? name="pascal.salaun_nbAtt_.png" from unknown[192.168.1.4]; \ from=frodo to= n.sa quet@ lapo ste.n etfrodo proto=ESMTP helo=<[192.168.1.4]>: ThisFileName=pascal.salaun_nbAtt_.png. n.sa quet@ lapo ste.n et
inc.regex.klmsLine = re.compile(r"(?P<date>.{6}) (?P<hour>.{8}) .* KLMS: (?P<status>.*): message-id=(?P<messageid>.*): relay.* av-status=(?P<avstatus>.*), ap-status=(?P<apstatus>.*), as-status=(?P<asstatus>.*),.*") |
KLMS Jun 8 10:30:00 toto4 KLMS: clean: message-id="D2D75237B513CA42B5E59766133F55003F60695C@ex-mbx1.siege.grouponet.com": relay-ip="212.99.25.65": action="Skipped": rules="1": size=3458: mail-from="technique@toto.com": rcpt-to="pascal.salaun@mclabosse.fr": av-status="Clean", ap-status="Clean", as-status="Clean", cf-status="NotScanned, disabled by settings".
inc.regex.qmgrLine = re.compile(r"(?P<date>.{6}) (?P<hour>.{8}) (.*)(postfix/qmgr)\[(\d+)\]: (?P<queueid>.*): from=<(?P<from>.*)>, size=(?P<size>\d+), nrcpt=(?P<nrcpt>\d+).*") |
Get originator, volume and number of recip Aug 22 15:38:15 galadriel postfix/qmgr[4158]: 7E83C9E4318: from=frodo, size=1767, nrcpt=1 (queue active) n.sa quet@ lapo ste.n et
inc.regex.smtpdLine = re.compile(r"(?P<date>.{6}) (?P<hour>.{8}) (.*)(postfix/smtpd)\[(\d+)\]: (?P<queueid>.*): client=(?P<server>.*)(?:(, .*)+)?") |
Get smtpd queueid on connection Aug 22 15:38:15 galadriel postfix/smtpd[29211]: 7E83C9E4318: client=.
inc.regex.smtpLineDSN2 = re.compile(r"(?P<date>.{6}) (?P<hour>.{8}) (.*)(postfix/)(.*)\[(\d+)\]: (?P<queueid>.*): to=<(?P<recip>.*?)(?:>, orig_to=<(?P<orig>.*?))?>, (.*)status=sent.*") |
Get list of destinators (dsn=2.
*.*) Apr 9 09:40:51 uruviel postfix/smtp[13879]: 22272341A57: to=frodo, relay=127.0.0.1[127.0.0.1]:10024, delay=7.6, delays=2.1/0.03/0.04/5.5, dsn=2.0.0, status=sent (250 2.0.0 from MTA(smtp:[127.0.0.1]:10025): 250 2.0.0 Ok: queued as 2004B341A80) n.sa quet@ lapo ste.n et
inc.regex.smtpLineDSN4 = re.compile(r"(?P<date>.{6}) (?P<hour>.{8}) (.*)(postfix/)(.*)\[(\d+)\]: (?P<queueid>.*): to=<(?P<recip>.*?)(?:>, orig_to=<(?P<orig>.*?))?>, (relay=.*)?(.*)status=deferred.*") |
Get list of deferred destinator (dsn=4.
*.*)
inc.regex.smtpLineDSN5 = re.compile(r"(?P<date>.{6}) (?P<hour>.{8}) (.*)(postfix/)(.*)\[(\d+)\]: (?P<queueid>.*): to=<(?P<recip>.*?)(?:>, orig_to=<(?P<orig>.*?))?>, (relay=.*)?(.*)status=bounced.*") |
Get list of deferred destinator (dsn=5.
*.*)
inc.regex.smtpRemoved = re.compile(r"(?P<date>.{6}) (?P<hour>.{8}) (.*)(postfix/qmgr)\[(\d+)\]: (?P<queueid>.*): removed") |
Get smtpd queueid before disconnection (file removed from spool) Apr 30 00:07:56 uruviel postfix/qmgr[4321]: 5141E341A1B: removed.