Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
sp_gdi_lab
Participant

what does action=bypass mean for product="Anti-Spam and Email Security"

I have some logs generated from the product "Anti Spam & Email Security" which has action=Bypass in it. Does anyone know what action=bypass signifies in context with the given product?

Is the email being sent, delivered to the desired address?

Is the email being sent, blocked by the security engine?

Or is the email quarantined somewhere by the security engine?

 

0 Kudos
7 Replies
_Val_
Admin
Admin

Can you share a sample log, please?

0 Kudos
sp_gdi_lab
Participant

Here is the sample log

Aug 28 08:54:36 1.1.1.0 time=1693202076|hostname=lab-hostname-sample|product=Anti-Spam and Email Security|action=Bypass|ifdir=inbound|ifname=eth0|loguid={0x64ec369d,0xc5,0xe07fa8c0,0x205ec071}|origin=1.1.1.1|originsicname=CN\=il-dmz-tls-05.sample.com,O\=abc..8ye75g|sequencenum=3|time=1693202076|version=5|dst=1.1.1.2|email_control=Allow List|email_spam_category=Non Spam|proto=6|recipients_number=0|rule=0|s_port=28843|service=25|src=1.1.1.3
0 Kudos
_Val_
Admin
Admin

This log says, your Email security was bypassed because the email belongs to your "Non Smap" list. It was allowed to pass through.

_Val_
Admin
Admin

Also, it looks to be the sysog entry. What about the actual log it belongs to? Do you have access to SmartConsole to see one?

0 Kudos
sp_gdi_lab
Participant

No, I don't have access to SmartConsole to view the log.

0 Kudos
_Val_
Admin
Admin

In this case, it is advisable to talk to the policy owners then, to understand the logs better, and the policy itself as well.

0 Kudos
the_rock
Legend
Legend

As description says, if action is bypass, then nothing was rejected or dropped.

Best,

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events