Solved

Event log Analyzing

Posted on 2008-10-10
14
206 Views
Last Modified: 2011-10-19
Hi

i have attached one Event log. This Event Log at 5 am ( and no body tryed to send email to this address) still i am seeing this log in event  log
i already setup my server as http://support.microsoft.com/kb/843106 saing

my understanding is , 1) some one tryed to realy to sales@chshel.net by using  my server but my server  refusing to realy. hense i am seeting this event log

is that right ??

Or 2) some one tryed to realy by using  my server and myserver actually relyed to that domain  but it got refused from chsel.net server so i am seeing this log in my event log ??

Please let me know, i am really worring .






Compromised2.GIF
0
Comment
Question by:fosiul01
  • 8
  • 6
14 Comments
 
LVL 35

Expert Comment

by:rakeshmiglani
ID: 22685194
>some one tryed to realy to sales@chshel.net by using  my server but my server  refusing to realy.
That is correct.
0
 
LVL 35

Expert Comment

by:rakeshmiglani
ID: 22685198
>some one tryed to realy to sales@chshel.net by using  my server but my server  refusing to realy.
That is correct.
0
 
LVL 29

Author Comment

by:fosiul01
ID: 22685220
hi thanks, is there any way to create event log as soon as Exchange server will realy any email ??( offcourse authenticate but unauthenticate aswell)

0
 
LVL 35

Expert Comment

by:rakeshmiglani
ID: 22685233
you might want to check the diagnostic logging for the server in the ESM.
there are quite a lot of options that you can set there.
0
 
LVL 29

Author Comment

by:fosiul01
ID: 22685242
you meant , message tracking ??

but with message tracking everything comes up, incomming , outgoing ..

i just want to check outgoing messages
0
 
LVL 35

Expert Comment

by:rakeshmiglani
ID: 22685255
no, i meant diagnostic logging from the exchange server properties in the Exchange system manager.
0
 
LVL 29

Author Comment

by:fosiul01
ID: 22685269
while i check diagnostic login please check the bellow

Please check the bellow picture, 5 minutes ago it came to my event log

does this mean Sameting is not it ?? some one is trying to realy mail via my server but my server is refusing to realy ??


compromised4.GIF
0
Enterprise Mobility and BYOD For Dummies

Like “For Dummies” books, you can read this in whatever order you choose and learn about mobility and BYOD; and how to put a competitive mobile infrastructure in place. Developed for SMBs and large enterprises alike, you will find helpful use cases, planning, and implementation.

 
LVL 29

Author Comment

by:fosiul01
ID: 22685275
diagnostic logging from the exchange server properties in the Exchange system manager.  == is there any tutorial for that

i am not expert in exchange.
how will i do that ??
0
 
LVL 35

Expert Comment

by:rakeshmiglani
ID: 22685282
correct.
0
 
LVL 35

Expert Comment

by:rakeshmiglani
ID: 22685292
0
 
LVL 29

Author Comment

by:fosiul01
ID: 22685322
Hi thanks for that link

as you can see, i realy enable Msexchagne transport

but which service and categories do i have to select for viewing - all out going email eamil in event log ??
0
 
LVL 35

Expert Comment

by:rakeshmiglani
ID: 22685509
categorie can be SMTP Protocol
0
 
LVL 29

Author Comment

by:fosiul01
ID: 22685534
HI thanks again
SMTP protocol is set as medium

but i am not seeting any log when email is going out
0
 
LVL 35

Accepted Solution

by:
rakeshmiglani earned 500 total points
ID: 22685950
if you set that to maximum do you get any more details?
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Learn to move / copy / export exchange contacts to iPhone without using any software. Also see the issues in configuration of exchange with iPhone to migrate contacts.
Find out what you should include to make the best professional email signature for your organization.
In this video we show how to create an email address policy in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.:  First we need to log into the Exchange Admin Center. Navigate to the Mail Flow…
This video discusses moving either the default database or any database to a new volume.

863 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

22 Experts available now in Live!

Get 1:1 Help Now