Mail Package
The mail package recognizes SMTP traffic on your network. There is package-wide N code
(meaning that it is shared among several backends) that decodes SMTP transactions and
passes some of the recovered information to the various backends in the package.
You can disable individual backends, and the mail package continues to function.
Backends
- bulk - A list backend that lists individual mail transactions. It
makes a list of:
- who is sending mail
- what host they are sending mail from
- how many recipients each message has (this counts recipients in a single transaction,
not messages that are sent separately.
- bulk_hist - A histogram backend that counts how many messages a
user/host sends. It records:
- mail sender
- the host from which the mail was sent
- od - A list backend of mail usage in your organization. It makes
a list of:
- source host
- destination host
- mail sender
- mail recipient
- time of the message
|