Internally generated spam

I have a client who is receiving lots of random and quite obvious spam. I think the spam is being generated by a rogue PC on our network rather than coming from outside, but I need advice on how to track this down.  I have a Draytek router. I blocked port 25 for everyone except our Exchange Server and enabled syslog but I don't know how to find or interpret the output.  Can someone please provide some useful guidance here.  Thanks.
Alan BatemanDirectorAsked:
Who is Participating?
 
Pradeep DubeyConnect With a Mentor ConsultantCommented:
0
 
Alan BatemanDirectorAuthor Commented:
OK. I've looked at using Wireshark. However if I don't know which PC on my network is the 'spammer' , I don't know which PC to install Wireshark on.  I do not have a 'mirrored port' on my switch. It is a simple unmanaged switch. Is there a way to monitor this in the router. ?
0
 
Alan BatemanDirectorAuthor Commented:
Abandoned this question.  Wireshark may have been the way to go, but I have no idea how to set it up and use it.
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.