Where can I find mail related logs? (/var/log/mail.log is empty)
81 views
Skip to first unread message
bug...@gmail.com
unread,
Mar 24, 2015, 10:07:59 AM3/24/15
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to securit...@googlegroups.com
Hi,
On a fresh Security Onion install, I am trying to see system logs related to sending/receiving email. I have ELSA enabled.
The problem is that the following files is always empty, not matter what I do with "mail":
/var/log/mail.*
Is this because I have ELSA enabled?
I checked and can confirm the following service is running (service name status)
syslog-ng
I suspect this is normal behaviour? since I am using ELSA?
Could someone please let me know what query I need to enter in ELSA to see logs related to mail activities?
If I wanted to enable (and maybe duplicate) logs to /var/log/mail.*, I guess I would have to edit the /etc/syslog-ng/syslog-ng.conf
but wanted to check if that information is already available somewhere! :)
Cheers,
Bugs.
Doug Burks
unread,
Mar 24, 2015, 10:17:11 AM3/24/15
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to securit...@googlegroups.com
Hi Bugs,
Yes, this is because you have ELSA enabled. Go to the ELSA query
menu, click Host Logs, and then click "Syslog-NG (Program)" and see if
your mail logs are listed there.