I have a site running Symantec mail security for Exchange 5. Every morning, at around the same time smse reports an outbreak because of emails with the same subject, about 200 of them hit the server. I've checked the application log, but there's no information in there aside from a generic message saying there's an outbreak.
What I need to do is find out where these emails are coming from so I can just reject them without getting the outbreak notification every day. But I can't find anywhere the details of the emails, eg, they're not in quarantine, they're not being processed.
Anyone know where I should be looking to get the information I need in order to block these emails?