PostFix Mail Transfer Agent 샘플 이벤트 메시지
이 샘플 이벤트 메시지를 사용하여 IBM QRadar와의 성공적인 통합을 확인하십시오.
중요: 형식화 문제로 인해 메시지 형식을 텍스트 편집기에 붙여넣은 후 캐리지 리턴 또는 줄 바꾸기 문자를 제거하십시오.
Syslog 프로토콜을 사용할 때 PostFix Mail Transfer Agent 샘플 메시지
샘플 1: 다음 샘플 이벤트 메시지는 이메일이 성공적으로 발송되었음을 표시합니다.
<22>Mar 5 13:09:45 postfix.mailtransferagent.test postfix/smtpd[7609]: B83C6210AB: client=unknown[192.168.0.14] message-id=<27914646.772901551755385716.JavaMail.root@testsrv1> from=<user4@exampledomain.test>, size=564564, nrcpt=1 (queue active) to=<user01@host.example.test>, relay=apc.olc.protection.server.test[192.168.126.33]:25, delay=3.4, delays=0.03/0/0.62/2.7, dsn=2.6.0, status=sent (250 2.6.0 <27914646.772901551755385716.JavaMail.root@testsrv1> [InternalId=19877108654932, Hostname=SERVER.PROD.EXAMPLE.TEST] 570417 bytes in 2.113, 263.513 KB/sec Queued mail for delivery -> 250 2.1.5) removed
| QRadar 필드 이름 | 이벤트 페이로드에서 강조표시된 값 |
|---|---|
| 이벤트 ID | B83C6210AB |
| 수신인 수 (사용자 정의 특성) | 1 |
| username | user4@+exampledomain.test |
| 원래 호스트 (사용자 정의 특성) | exampledomain.test |
| 원래 사용자 (사용자 정의 특성 | user4@+exampledomain.test |
| 수신인 호스트 (사용자 정의 특성) | host.example.test |
| 수신자 사용자 (사용자 정의 특성) | user01@+host.example.test |
| 소스 IP | 192.168.0.14 |
| 대상 포트 | 192.168.126.33 |
| 대상 포트 | 25 |
샘플 2: 다음 샘플 이벤트 메시지는 이메일이 수신되었음을 표시합니다.
<22>Jun 19 15:41:12 postfix.mailtransferagent.test postfix/qmgr[12345]: FFFFFFF: from=<User.Name@domain1.test>, size=3806, nrcpt=1 (queue active)
| QRadar 필드 이름 | 이벤트 페이로드에서 강조표시된 값 |
|---|---|
| 이벤트 ID | qmgr |
| username | User.Name@domain1.test |
| 메시지 크기 (사용자 정의 특성) | 3806 |
| MessageID (사용자 정의 특성) | FFFFFFF |
팁:
IBM® QRadar® Custom Properties for Postfix 를 사용하여 Custom Properties for Postfix 배치를 자세히 모니터할 수 있습니다. Postfix 사용자 정의 이벤트 특성은 로그 소스에서 특정 이벤트 데이터를 정규화하여 QRadar 검색 및 보고서를 확장합니다. IBM QRadar Custom Properties for Postfix 컨텐츠 팩이 시스템에 설치되어 있지 않으면 IBM X-Force Exchange 웹 사이트 (https://exchange.xforce.ibmcloud.com/hub) 에서 다운로드하십시오.