Summary
Currently it is not possible to query the logs for the Content Scanning (Spam) detection filter directly from the ScanMail for Microsoft Exchange administrator console.
This article explains different ways to query those logs.
To perform the Content Scanning (Spam) log query, do the steps below:
- Send the logs to Apex Central.
- On the SMEX web console, navigate to Administration > Apex Central Settings.
- Tick the Send spam logs to Apex Central option.
Those logs will appear in Apex Central under the "Content violation category".
Click the image to enlarge.
- Send logs via syslog to a third-party log management system.
- In the Apex Central console, go to Logs > Log Forwarding.
- Under Log Type, make sure the Spam Prevention is selected.
Click the image to enlarge.
The log forwarding setting is only available starting with ScanMail for Exchange 14.
More information regarding the format of the syslog events sent by SMEX can be found in the following KB article: ScanMail for Exchange (SMEX) 14.0 Syslog content mapping guide