Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Tracing Outlook client activity to IP address 1

Status
Not open for further replies.

grubs4fishn

IS-IT--Management
May 20, 2008
3
US
I have a bot on an internal pc that kicks off a few outbound SPAM messages per day. I want to track it down to it's netbios name or IP address for remediation purposes. I currently see no way to accomplish this. I have tried EXMON.EXE but it does not gather anything helpful. I can see the NDRs generated by the bot in the application logs, but nothing there to identify the source. Any help here would be greatly appreciated. I have a packet sniff of the behavior, but am not sharp enough to make much out of it. Thanks in advance..
 
Look at the exchange server logs, the client IP address is listed.
 
Can you be more detailed. I looked there first. I see no client server entries in the event logs. There may be a way to crank up the logging, but it is very complex what you can do there and be default most loging is turn off.
 
I did not mean the event logs, but the server tracking logs (if you have them enabled). They are server_name.log. Look on your exchange server in ESM and look at the properties of the server. It will show all traffic going in/out of the exchange server.
 
SilentSam - that's nicely put, concise and helpful. Have a star from me for helping others.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top