Skip to content
Geek and I
Go back

Sumo Logic + Email Dashboard

Updated:
Mike Horwath3 min read

I am feeding my syslog files into a Sumo Logic collector which includes the mail logs from Postfix (and some Dovecot and Fortigate mentions).

2015-06-29-sumologic-email-flow

There is a lot going on in this dashboard. (and I have a lot of tabs open in my browser - don’t hate!)

Dashboards in Sumo Logic are an easy and quick way to visualize data you have information for. In earlier posts I showed data from a Fortigate firewall to display bandwidth hogs and performance graphs.

But I wanted to see how my mail server(s) are doing.

So I built a sample dashboard to do just that.

RowLeftCenterRight
1GeoIP of incoming connectionsPostfix inbound/outboundPostfix delivery size and # recipients
2GeoIP of outgoing connectionsmilter rejection hostsDNSBL rejection hosts
3GeoIP of Dovecot connectionsDovecot size of in/out trafficPostfix rejections per hour
4Fortigate Spam ProfilesTop 10 Postfix local destinations—

Included below are the relevant searches needed to build a dashboard as pictured above.

GeoIP of incoming connections:

_index=unix_logs _sourceName="mail system"
((postfix/postscreen AND (DISCONNECT)) OR (SecureMail))
| parse regex "(?P<client_ip>\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})"
| lookup latitude, longitude, country_code, country_name, region, city, postal_code, area_code, metro_code from geo://location on ip = client_ip
| count by latitude, longitude, country_code, country_name, region, city, postal_code, area_code, metro_code
| sort _count

Postfix inbound/outbound:

_index=unix_logs _sourceName="mail system"
AND NOT (127.0.0.1 OR 192.168.110.218)
AND (postfix/smtp OR postfix/smtpd)
| parse regex ".*: connect from .*\[(?P<src_ip>\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})" nodrop
| parse regex ":.*: to=.*\[(?P<dst_ip>\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}).*=sent"
| split src_ip delim='.' extract 1 as src_num_ip1
| split dst_ip delim='.' extract 1 as dst_num_ip1
| if ((src_num_ip1 >= "1"), 1, 0) as inbound
| if ((dst_num_ip1 >= "1"), 1, 0) as outbound
| timeslice 60m
| sum(inbound) as inbound, sum(outbound) as outbound by _timeslice

Postfix delivery size and # recipients:

_index=unix_logs _sourceName="mail system" postfix/qmgr
| parse "size=*, nrcpt=* " as size, rcpt
| timeslice 60m
| (size/1000000) as mbytes_in
| sum(mbytes_in) as size, sum(rcpt) as recipients by _timeslice

GeoIP of outgoing connections:

_index=unix_logs _sourceName="mail system"
postfix/smtp AND !(127.0.0.1 OR clamsmtpd OR "TLS connection established")
AND "250 "
| parse regex "relay=.*\[(?P<client_ip>\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})\]:"
| lookup latitude, longitude, country_code, country_name, region, city, postal_code, area_code, metro_code from geo://location on ip = client_ip
| count by latitude, longitude, country_code, country_name, region, city, postal_code, area_code, metro_code
| sort _count

milter rejection hosts:

_index=unix_logs _sourceName="mail system" (postfix/cleanup AND " milter-reject: ")
| parse regex "\[(?P<block_ip>\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})"
| count as count by block_ip
| order by count
| limit 10

DNSBL rejection hosts:

_index=unix_logs _sourceName="mail system" (postfix/postscreen AND " DNSBL ")
| parse "rank * " as rank nodrop
| parse regex "\[(?P<block_ip>\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})"
| count as count by block_ip, rank
| order by count
| limit 20

GeoIP of Dovecot connections:

_index=unix_logs _sourceName="mail system"
dovecot: AND (imap-login: OR pop3-login)
| parse regex "rip=(?P<client_ip>\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}),"
| lookup latitude, longitude, country_code, country_name, region, city, postal_code, area_code, metro_code from geo://location on ip = client_ip
| count by latitude, longitude, country_code, country_name, region, city, postal_code, area_code, metro_code
| sort _count

Dovecot size of in/out traffic:

_index=unix_logs _sourceName="mail system"
"dovecot:" !"Debug:" "Connection closed "
| parse "imap(*)" as username nodrop
| keyvalue regex "=(\d+)" keys "in", "out" as input, output
| timeslice 60m
| (input/1000000) as mbytes_in
| (output/1000000) as mbytes_out
| sum(mbytes_in) as inbound, sum(mbytes_out) as outbound by _timeslice

Postfix rejections per hour:

_index=unix_logs _sourceName="mail system" " 5.7.1 "
| parse regex "milter-reject: END-OF-MESSAGE from .*\[(?P<milter_src_ip>\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})" nodrop
| parse regex "NOQUEUE: reject: .*from .*\[(?P<rbl_src_ip>\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})"
| split milter_src_ip delim='.' extract 1 as milter_num_ip1
| split rbl_src_ip delim='.' extract 1 as rbl_num_ip1
| if ((milter_num_ip1 >= "1"), 1, 0) as milter
| if ((rbl_num_ip1 >= "1"), 1, 0) as rbl
| timeslice 60m
| sum(milter) as milter, sum(rbl) as rbl by _timeslice

Fortigate Spam Profiles:

_index=security_logs _sourceCategory=fw_security "service=SMTP"
| parse "profile=* action=* " as profile, action
| count as count profile
| order by count

Top 10 Postfix local destinations:

_index=unix_logs _sourceName="mail system"
!(127.0.0.1 OR clamsmtpd:) "status=sent"
| parse " to=<*>, " as orig_destination
| toLowerCase(orig_destination) as destination
| timeslice 60m
| count as count destination
| order by count


Related Posts

Previous Post
Sumo Logic + Log Volume Breakdown
Next Post
Sumo Logic + Fortigate + Bandwidth Hogs