I am trying to create a script for listing emails count which are blocked by Transport Rules. I have totally three transport rules in place, 1. Block credit card and SSN, 2. Block Driver License, 3. Block Driver License in attachments. The whole purpose of this script is to categorize emails count based on transport rules, so that we can see how many hits for Credit card, SSN and Driver license. I have searched couple of articles but that doesn't give me the exact results what i was looking for.
Do i need to put condition based on Message body (for ex.. Messagebody contains "credit card" and Eventid contains "Fail" or "DSN"?) or Based on Transport rules Name.
It would be a great help if someone can help me with this,