Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
Hi all,just updating Cisco ESA VM to AsyncOS 14.I've the following error: /nextroot: write failed, filesystem is full the partition info via ipcheck: Root 400MB 52% Nextroot 400MB 108% Var 400MB 16% ...
Hi allusing Consolidate event Logs does not send the smtp auth id to the siem, is it possible to edit those type of logging and, maybe, add a custom line?Thanks
Hi all,i'm testing ESA for outgoing email sending, just configured LDAP and it works.The problem is if i set as sender addres "[email protected]" it will send the email even if i am not in right to do this!Since i am only authorized to send email fr...
Hi all,we've got two vESAs with two mx records, both 10 and 10.if we send all traffic through all two of them everything works fine, or at least acceptable.If we send all traffic only to one appliance we've got the following queue working rate: Time...
Hi all,apart from this smtp auth id that is not going to appear into logs, i try to explain better what i do for those tests:i use a simple windows smpt tool.then i put:1. smtp mail server, so my ESA2. username and password, in this case for authenti...
Hi,i already have the x-smtpauth into log subscriptions.The problem with filters is that if you add a custom line on the email's header it will not be reported to any siem, so not useful to track at a glance, and, anyway, the problem still remains, a...
Hi Libin,i've found this: Msg_Authentication: if (smtp-auth-id-matches("*Any")){ # Always include the original authentication credentials in a # special header. insert-header("X-SMTPAUTH", "$SMTPAuthID"); if (smtp-auth-id-matches("*FromAd...
Well... how can i use a filter for this? I suppose smtp auth is the real deal because it should do a check against AD and see if user A has into his properties the email from which he's sending the email, or not? BR Salvatore