<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.tetrain.com/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Shashanksharma</id>
	<title>TetraWiki - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.tetrain.com/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Shashanksharma"/>
	<link rel="alternate" type="text/html" href="https://wiki.tetrain.com/index.php?title=Special:Contributions/Shashanksharma"/>
	<updated>2026-07-25T07:22:54Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.43.9</generator>
	<entry>
		<id>https://wiki.tetrain.com/index.php?title=ALPHA_Cluster_Troubleshooting&amp;diff=1615</id>
		<title>ALPHA Cluster Troubleshooting</title>
		<link rel="alternate" type="text/html" href="https://wiki.tetrain.com/index.php?title=ALPHA_Cluster_Troubleshooting&amp;diff=1615"/>
		<updated>2014-05-03T09:45:12Z</updated>

		<summary type="html">&lt;p&gt;Shashanksharma: Blanked the page&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Shashanksharma</name></author>
	</entry>
	<entry>
		<id>https://wiki.tetrain.com/index.php?title=ALPHA_Cluster_Troubleshooting&amp;diff=1614</id>
		<title>ALPHA Cluster Troubleshooting</title>
		<link rel="alternate" type="text/html" href="https://wiki.tetrain.com/index.php?title=ALPHA_Cluster_Troubleshooting&amp;diff=1614"/>
		<updated>2014-05-03T09:43:05Z</updated>

		<summary type="html">&lt;p&gt;Shashanksharma: Created page with &amp;quot; cs:Connected st:&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;Primary/Unknown&amp;#039;&amp;#039;&amp;#039; ds:UpToDate/DUnknown&amp;#039;&amp;#039;&amp;#039; r---  ns:0 nr:0 dw:1036 dr:3111 al:0 bm:98 lo:0 pe:0 ua:0 ap:0   (a) If the cluster (/OPT) is mounted on &amp;#039;&amp;#039;&amp;#039;P...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt; cs:Connected st:&#039;&#039;&#039;&#039;&#039;&#039;Primary/Unknown&#039;&#039;&#039; ds:UpToDate/DUnknown&#039;&#039;&#039; r---&lt;br /&gt;
 ns:0 nr:0 dw:1036 dr:3111 al:0 bm:98 lo:0 pe:0 ua:0 ap:0 &lt;br /&gt;
&lt;br /&gt;
(a) If the cluster (/OPT) is mounted on &#039;&#039;&#039;Primary&#039;&#039;&#039; node and showing above error,then run the following commands.&lt;br /&gt;
&lt;br /&gt;
(1) drbdadm -- --discard-my-data connect all           (on &#039;&#039;&#039;Node2&#039;&#039;&#039; with &amp;quot;bad&amp;quot; data)&lt;br /&gt;
&lt;br /&gt;
(2) drbdadm connect all                                (on &#039;&#039;&#039;Node1&#039;&#039;&#039; with &amp;quot;good&amp;quot; data)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
After running those commands check &#039;&#039;&#039;Node1&#039;&#039;&#039; .&lt;br /&gt;
&lt;br /&gt;
(3) service drbd status  (It will show that data is syncing to &#039;&#039;&#039;node2&#039;&#039;&#039; disk)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 cs:WFConnection st:&#039;&#039;&#039;&#039;&#039;&#039;Secondary/Unknown&#039;&#039;&#039;&#039;&#039;&#039; ds:&#039;&#039;&#039;UpToDate/DUnknown&#039;&#039;&#039; C r---&lt;br /&gt;
 ns:0 nr:0 dw:0 dr:0 al:0 bm:17 lo:0 pe:0 ua:0 ap:0 &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
(a) If the cluster (/OPT) is mounted on &#039;&#039;&#039;Secondary&#039;&#039;&#039; node and showing above error,then run the following commands.&lt;br /&gt;
&lt;br /&gt;
(1) drbdadm -- --discard-my-data connect all           (on &#039;&#039;&#039;Node1&#039;&#039;&#039; with &amp;quot;bad&amp;quot; data)&lt;br /&gt;
&lt;br /&gt;
(2) drbdadm connect all                                (on &#039;&#039;&#039;Node2&#039;&#039;&#039; with &amp;quot;good&amp;quot; data)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
After running this command check &#039;&#039;&#039;Node2&#039;&#039;&#039; .&lt;br /&gt;
&lt;br /&gt;
(3) service drbd status  (It will show that data is syncing to &#039;&#039;&#039;node1&#039;&#039;&#039; disk)&lt;/div&gt;</summary>
		<author><name>Shashanksharma</name></author>
	</entry>
	<entry>
		<id>https://wiki.tetrain.com/index.php?title=RDM_Implementation_Details_in_a_Single_html&amp;diff=1577</id>
		<title>RDM Implementation Details in a Single html</title>
		<link rel="alternate" type="text/html" href="https://wiki.tetrain.com/index.php?title=RDM_Implementation_Details_in_a_Single_html&amp;diff=1577"/>
		<updated>2014-03-02T05:01:54Z</updated>

		<summary type="html">&lt;p&gt;Shashanksharma: master ldap&amp;#039;s entries sorted properly. no changes have been made in terms of commands/file edit.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[category:RDM]]&lt;br /&gt;
&lt;br /&gt;
=Contents=&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Deafault ACLs==&lt;br /&gt;
-------------------------------&lt;br /&gt;
Default ACLs&lt;br /&gt;
-------------------------------&lt;br /&gt;
&lt;br /&gt;
To set defualt ACL, we have to set defualt permissions by below command.&lt;br /&gt;
Whenever a file will be created it&#039;s owner will be file creator and&lt;br /&gt;
permission will be as u:rwx,g:r-x,o:---&lt;br /&gt;
&lt;br /&gt;
#setfacl --set u::rwx,g::r-x,o::--- test&lt;br /&gt;
&lt;br /&gt;
below commands will set default acl to newly created files and directories.&lt;br /&gt;
&lt;br /&gt;
#setfacl -m d:u:a0016:rwx test&lt;br /&gt;
#setfacl -m d:u:a0019:rwx test&lt;br /&gt;
#setfacl -m d:u:a0032:r-x test&lt;br /&gt;
&lt;br /&gt;
But if these three users does not have a permissoin to access the test&lt;br /&gt;
dir, then please do set permission as given below&lt;br /&gt;
#setfacl -m u:a0016:rwx test&lt;br /&gt;
#setfacl -m u:a0019:rwx test&lt;br /&gt;
#setfacl -m u:a0032:r-x test&lt;br /&gt;
&lt;br /&gt;
This will give default permission to a Group.&lt;br /&gt;
#setfacl -m d:g:RADLH:rw- testdir&lt;br /&gt;
&lt;br /&gt;
==DNS==&lt;br /&gt;
&lt;br /&gt;
---------&lt;br /&gt;
DNS&lt;br /&gt;
---------&lt;br /&gt;
services of the DNS&lt;br /&gt;
&lt;br /&gt;
/etc/init.d/named start&lt;br /&gt;
/etc/init.d/named stop&lt;br /&gt;
/etc/init.d/named restart&lt;br /&gt;
/etc/init.d/named status&lt;br /&gt;
&lt;br /&gt;
config file path&lt;br /&gt;
vim /var/named/chroot/etc/named.conf&lt;br /&gt;
&lt;br /&gt;
zone files path&lt;br /&gt;
/var/named/chroot/var/named/&lt;br /&gt;
&lt;br /&gt;
dns log file&lt;br /&gt;
tail -f /var/log/messages&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==OpenLDAP master/master replication==&lt;br /&gt;
---------------------------------&lt;br /&gt;
OpenLDAP master/master replication&lt;br /&gt;
---------------------------------&lt;br /&gt;
master 172.20.1.14&lt;br /&gt;
slave 172.20.1.24&lt;br /&gt;
binddn=&amp;quot;cn=manager,dc=rdm,dc=co,dc=in&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
on master&lt;br /&gt;
&lt;br /&gt;
vim /etc/openldap/slapd.conf&lt;br /&gt;
-------------------------------------&lt;br /&gt;
        replica host=172.20.1.24:389&lt;br /&gt;
        binddn=&amp;quot;cn=Manager,dc=rdm,dc=co,dc=in&amp;quot;&lt;br /&gt;
        bindmethod=simple&lt;br /&gt;
        credentials=rdmsecret4u001&lt;br /&gt;
        replogfile /var/lib/ldap/openldap-master-replog&lt;br /&gt;
-------------------------------------&lt;br /&gt;
&lt;br /&gt;
touch /var/lib/ldap/ldaprep.log&lt;br /&gt;
chown ldap.ldap /var/lib/ldap/ldaprep.log&lt;br /&gt;
above file should be writable by ldap, whatever chages are made to ldap are written to this file and when they are reflicated to slave they were be deleted from the file.&lt;br /&gt;
&lt;br /&gt;
on slave&lt;br /&gt;
&lt;br /&gt;
vim /etc/openldap/slapd.conf&lt;br /&gt;
-------------------------------------&lt;br /&gt;
        updatedn &amp;quot;cn=Manager,dc=rdm,dc=co,dc=in&amp;quot;&lt;br /&gt;
        updateref ldap://172.20.1.14&lt;br /&gt;
-------------------------------------&lt;br /&gt;
nessus&lt;br /&gt;
&lt;br /&gt;
install&lt;br /&gt;
add user&lt;br /&gt;
registor&lt;br /&gt;
download plugin&lt;br /&gt;
start if not&lt;br /&gt;
then start services directly.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==NTP Server==&lt;br /&gt;
&lt;br /&gt;
---------&lt;br /&gt;
NTP Server&lt;br /&gt;
---------&lt;br /&gt;
NTP services&lt;br /&gt;
/etc/init.d/ntpd status&lt;br /&gt;
/etc/init.d/ntpd stop&lt;br /&gt;
/etc/init.d/ntpd restart&lt;br /&gt;
/etc/init.d/ntpd status&lt;br /&gt;
&lt;br /&gt;
---------&lt;br /&gt;
NTP Client&lt;br /&gt;
---------&lt;br /&gt;
below two commands can be used on linux ntp clients to see the status and query to NTP server&lt;br /&gt;
&lt;br /&gt;
ntpdc -p&lt;br /&gt;
ntpdc -l&lt;br /&gt;
&lt;br /&gt;
==ossec agent linux==&lt;br /&gt;
&lt;br /&gt;
----------------------&lt;br /&gt;
ossec agent linux&lt;br /&gt;
----------------------&lt;br /&gt;
below command will be used to add/remove new ossec agents.&lt;br /&gt;
/var/ossec/bin/manage_agents&lt;br /&gt;
&lt;br /&gt;
below commands can be used to start/stop the ossec agent&lt;br /&gt;
&lt;br /&gt;
/var/ossec/bin/ossec-control start&lt;br /&gt;
/var/ossec/bin/ossec-control stop&lt;br /&gt;
/var/ossec/bin/ossec-control restart&lt;br /&gt;
/var/ossec/bin/ossec-control status&lt;br /&gt;
&lt;br /&gt;
ossec logs can be check by below command.&lt;br /&gt;
tail -f /var/ossec/logs/ossec.log &lt;br /&gt;
&lt;br /&gt;
ossec configuration file is &lt;br /&gt;
/var/ossec/etc/ossec.conf&lt;br /&gt;
&lt;br /&gt;
----------------------&lt;br /&gt;
ossec agent windows&lt;br /&gt;
----------------------&lt;br /&gt;
The ossec agent interface on windows can be started via start-&amp;gt;program-&amp;gt; ossec-&amp;gt;manage agent&lt;br /&gt;
&lt;br /&gt;
From this interface you can check the logs and config file.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==OSSEC Server==&lt;br /&gt;
&lt;br /&gt;
-----------------&lt;br /&gt;
OSSEC Server&lt;br /&gt;
-----------------&lt;br /&gt;
Use below commands start/stop the ossec services&lt;br /&gt;
&lt;br /&gt;
/var/ossec/bin/ossec-control status&lt;br /&gt;
/var/ossec/bin/ossec-control stop&lt;br /&gt;
/var/ossec/bin/ossec-control restart&lt;br /&gt;
/var/ossec/bin/ossec-control status&lt;br /&gt;
&lt;br /&gt;
ossec services log&lt;br /&gt;
tail -f /var/ossec/logs/ossec.log &lt;br /&gt;
&lt;br /&gt;
ossec alerts log&lt;br /&gt;
tail -f /var/ossec/logs/alerts/alerts.log&lt;br /&gt;
&lt;br /&gt;
ossec configuration file is &lt;br /&gt;
/var/ossec/etc/ossec.conf&lt;br /&gt;
&lt;br /&gt;
rootcheck/rootkit logs can be found at the below path&lt;br /&gt;
/var/ossec/queue/rootcheck/&lt;br /&gt;
&lt;br /&gt;
syscheck/integrity logs can be found at the below path&lt;br /&gt;
/var/ossec/queue/syscheck/&lt;br /&gt;
&lt;br /&gt;
Starting Second OSSEC server&lt;br /&gt;
---------------------------&lt;br /&gt;
when first ossec is not working then follows below process to up Second ossec server&lt;br /&gt;
login to 10.10.10.27 and change ip to 10.10.10.17(down first machine) and start ossec service&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
OSSIM&lt;br /&gt;
-------------&lt;br /&gt;
http://10.10.10.18/ossim/index.php&lt;br /&gt;
User : admin&lt;br /&gt;
Pass : &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Openldap Password Policy on 172.20.1.24==&lt;br /&gt;
&lt;br /&gt;
--------------------------&lt;br /&gt;
Openldap Password Policy on 172.20.1.24&lt;br /&gt;
--------------------------&lt;br /&gt;
&lt;br /&gt;
Password Policy is defined on the 172.20.1.24 server. Every day it will generate the email alerts for the locked and expired email accounts.&lt;br /&gt;
The attributes of this policy is as follows&lt;br /&gt;
&lt;br /&gt;
pwdMinAge: 1 minute&lt;br /&gt;
pwdMaxAge: 45 days&lt;br /&gt;
pwdMinLength: 7&lt;br /&gt;
pwdExpireWarning: 40 days&lt;br /&gt;
pwdGraceAuthNLimit: 3&lt;br /&gt;
pwdLockoutDuration: 10 minute&lt;br /&gt;
pwdMaxFailure: 5&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The policy can be change by http://172.20.1.24/phpldapadmin/htdocs/index.php and select &amp;quot;cn=Standard,ou=Policies,dc=rdm,dc=co,dc=in&amp;quot; and do the required change e.g. &lt;br /&gt;
&lt;br /&gt;
pwdExpireWarning, pwdGraceAuthNLimit, pwdLockoutDuration, pwdMinAge etc.&lt;br /&gt;
&lt;br /&gt;
--------------------------&lt;br /&gt;
Openldap Password Policy on 172.20.1.24&lt;br /&gt;
--------------------------&lt;br /&gt;
&lt;br /&gt;
yum install openldap-servers-overlays&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
vi /etc/openldap/slapd.conf&lt;br /&gt;
---------------------------&lt;br /&gt;
add below lines&lt;br /&gt;
&lt;br /&gt;
include /etc/ldap/schema/ppolicy.schema&lt;br /&gt;
&lt;br /&gt;
moduleload ppolicy&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
overlay ppolicy&lt;br /&gt;
ppolicy_default &amp;quot;cn=Standard,ou=Policies,dc=rdm,dc=co,dc=in&amp;quot;&lt;br /&gt;
ppolicy_use_lockout&lt;br /&gt;
ppolicy_hash_cleartext&lt;br /&gt;
&lt;br /&gt;
---------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
vi ppolicy.ldif&lt;br /&gt;
---------------------------&lt;br /&gt;
dn: ou=Policies,dc=rdm,dc=co,dc=in&lt;br /&gt;
ou: Policies&lt;br /&gt;
description: Directory policies.&lt;br /&gt;
objectclass: organizationalUnit&lt;br /&gt;
&lt;br /&gt;
dn: cn=Standard,ou=Policies,dc=rdm,dc=co,dc=in&lt;br /&gt;
cn: Standard&lt;br /&gt;
description: Standard password policy.&lt;br /&gt;
pwdAttribute: 2.5.4.35&lt;br /&gt;
pwdMinAge: 60&lt;br /&gt;
# 30 days: 60 sec * 60 min * 24 hr * 30 days&lt;br /&gt;
pwdMaxAge: 2592000&lt;br /&gt;
pwdCheckQuality: 1&lt;br /&gt;
pwdMinLength: 7&lt;br /&gt;
# Warn three days in advance&lt;br /&gt;
pwdExpireWarning: 2160000&lt;br /&gt;
pwdGraceAuthNLimit: 3&lt;br /&gt;
pwdLockout: TRUE&lt;br /&gt;
pwdLockoutDuration: 1200&lt;br /&gt;
pwdMaxFailure: 5&lt;br /&gt;
pwdFailureCountInterval: 1200&lt;br /&gt;
pwdMustChange: TRUE&lt;br /&gt;
pwdAllowUserChange: TRUE&lt;br /&gt;
pwdSafeModify: TRUE&lt;br /&gt;
objectclass: device&lt;br /&gt;
objectclass: pwdPolicy&lt;br /&gt;
---------------------------&lt;br /&gt;
&lt;br /&gt;
ldapadd -acvx -D&amp;quot;cn=manager,dc=rdm,dc=co,dc=in&amp;quot; -w rdmsecret4u001 -f ppolicy.ldif&lt;br /&gt;
&lt;br /&gt;
/etc/init.d/ldap restart&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Email Alert Scripting&lt;br /&gt;
----------------------&lt;br /&gt;
&lt;br /&gt;
vim /root/ppolicy/ppolicy.sh &lt;br /&gt;
----------------------&lt;br /&gt;
#!/bin/sh&lt;br /&gt;
#search qmail users&lt;br /&gt;
ldapsearch  -x &#039;(&amp;amp;(objectclass=qmailUser))&#039; uid|grep uid:|tr -d &#039; &#039;|cut -d: -f2 &amp;gt; /root/ppolicy/email_users&lt;br /&gt;
#turncat user_expire and locked_user files.&lt;br /&gt;
echo &amp;gt; /root/ppolicy/user_expire&lt;br /&gt;
echo &amp;gt; /root/ppolicy/locked_user&lt;br /&gt;
#search for account expired users&lt;br /&gt;
for i in `cat /root/ppolicy/email_users`&lt;br /&gt;
do&lt;br /&gt;
ldapsearch  -x &amp;quot;(&amp;amp;(objectclass=qmailUser)(uid=$i)(pwdChangedTime&amp;lt;=`date &#039;+%Y%m%d%k%M%SZ&#039; -d &amp;quot;30 days ago&amp;quot;`))&amp;quot; uid|grep uid: |tr -d &#039; &#039; |cut -d: -f2 &amp;gt;&amp;gt; /root/ppolicy/user_expire&lt;br /&gt;
#search for account locked users&lt;br /&gt;
locked=`ldapsearch  -x &amp;quot;(&amp;amp;(objectclass=qmailUser)(uid=$i))&amp;quot; pwdGraceUseTime -LL |grep -c pwdGraceUseTime`&lt;br /&gt;
if [ &amp;quot;$locked&amp;quot; == &amp;quot;3&amp;quot; ]&lt;br /&gt;
then&lt;br /&gt;
echo $i &amp;gt;&amp;gt; /root/ppolicy/locked_user&lt;br /&gt;
fi&lt;br /&gt;
done&lt;br /&gt;
#generate alerts&lt;br /&gt;
sh /root/ppolicy/expireAlert.sh&lt;br /&gt;
----------------------&lt;br /&gt;
&lt;br /&gt;
vim /root/ppolicy/expireAlert.sh &lt;br /&gt;
----------------------&lt;br /&gt;
#!/bin/sh&lt;br /&gt;
#send email password expiration alert to user and edp&lt;br /&gt;
for i in `cat /root/ppolicy/user_expire`&lt;br /&gt;
do&lt;br /&gt;
cat /root/ppolicy/expiremsg |mail -s &amp;quot;Password Expiration Notice&amp;quot; $i@rdm.co.in&lt;br /&gt;
done&lt;br /&gt;
#send email to edp about locked users&lt;br /&gt;
cat /root/ppolicy/locked_user | mail -s &amp;quot;Email Account Locked Users &amp;quot; edp@rdm.co.in&lt;br /&gt;
----------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==NFS Details==&lt;br /&gt;
&lt;br /&gt;
----------&lt;br /&gt;
NFS&lt;br /&gt;
----------&lt;br /&gt;
below command can be used to start/stop NFS service&lt;br /&gt;
&lt;br /&gt;
/etc/init.d/nfs start&lt;br /&gt;
/etc/init.d/nfs stop&lt;br /&gt;
/etc/init.d/nfs restart&lt;br /&gt;
/etc/init.d/nfs status&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Qmail Details ==&lt;br /&gt;
-----------&lt;br /&gt;
Qmail&lt;br /&gt;
-----------&lt;br /&gt;
There are two qmail instance.&lt;br /&gt;
First instance sends(local) and receive all mails.&lt;br /&gt;
Second instance sends non-local mails &lt;br /&gt;
&lt;br /&gt;
qmailctl stat&lt;br /&gt;
&lt;br /&gt;
vi /etc/inittab ;init q&lt;br /&gt;
--------------------------------------&lt;br /&gt;
#SV:123456:respawn:/command/svscanboot&lt;br /&gt;
&lt;br /&gt;
comment will stop qmail&lt;br /&gt;
and uncoment will start the qmail server&lt;br /&gt;
&lt;br /&gt;
SV:123456:respawn:/command/svscanboot&lt;br /&gt;
--------------------------------------&lt;br /&gt;
&lt;br /&gt;
below commands can be used to see the current logs.&lt;br /&gt;
&lt;br /&gt;
tail -f /var/log/qmail/qmail-send/current |tai64nlocal&lt;br /&gt;
tail -f /var/log/qmail/qmail-smtp/current |tai64nlocal&lt;br /&gt;
tail -f /var/log/qmail/qmail-pop3d/current |tai64nlocal &lt;br /&gt;
 &lt;br /&gt;
tail -f /var/log/qmail2/qmail2-send/current |tai64nlocal&lt;br /&gt;
tail -f /var/log/qmail2/qmail2-smtp/current |tai64nlocal&lt;br /&gt;
&lt;br /&gt;
tail -f /var/log/maillog&lt;br /&gt;
&lt;br /&gt;
below log file is of scanner logs&lt;br /&gt;
tail -f /var/spool/qmailscan/qmail-queue.log &lt;br /&gt;
&lt;br /&gt;
commands to strat and stop spamassassin.&lt;br /&gt;
&lt;br /&gt;
/etc/init.d/spamassassin status&lt;br /&gt;
/etc/init.d/spamassassin stop&lt;br /&gt;
/etc/init.d/spamassassin restart&lt;br /&gt;
&lt;br /&gt;
to start imap service&lt;br /&gt;
/etc/init.d/imap start&lt;br /&gt;
&lt;br /&gt;
to start imapproxy&lt;br /&gt;
/usr/local/sbin/in.imapproxyd&lt;br /&gt;
&lt;br /&gt;
to start clam Anti Virus servie&lt;br /&gt;
/usr/local/sbin/clamd&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
There are two nfs mounting. First qmailnfs and second is sophosAV &lt;br /&gt;
&lt;br /&gt;
below command will mount the NFS from 10.10.10.16 in /home/vmail&lt;br /&gt;
mount -t nfs -o tcp,rsize=32768,wsize=32768 10.10.10.16:/home/vmail /home/vmail/&lt;br /&gt;
&lt;br /&gt;
The mounting parameter for sophos is configured into /etc/fstab.&lt;br /&gt;
to mount sophos below command can be used.&lt;br /&gt;
mount -a&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
below commands are for ldap server&lt;br /&gt;
/etc/init.d/ldap status&lt;br /&gt;
/etc/init.d/ldap stop&lt;br /&gt;
/etc/init.d/ldap restart&lt;br /&gt;
/etc/init.d/ldap status&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Other Details==&lt;br /&gt;
&lt;br /&gt;
rsync_ossec&lt;br /&gt;
----------------&lt;br /&gt;
15 * * * * rsync -auvrl --delete /var/ossec rsync://10.10.10.27/OSSEC&lt;br /&gt;
&lt;br /&gt;
above cron job runs on every hour at 15 Minutes&lt;br /&gt;
&lt;br /&gt;
backup from 10.10.10.17:/var/ossec 10.10.10.27:/var/ossec&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
rsync_qmailnfs&lt;br /&gt;
&lt;br /&gt;
0 2 * * * /root/rsync_qmailnfs.sh&lt;br /&gt;
above cron job take mail backup&lt;br /&gt;
&lt;br /&gt;
backup from 10.10.10.16:/home/vmail to 10.10.10.26:/home/vmail&lt;br /&gt;
rsync_sambanfs&lt;br /&gt;
----------------&lt;br /&gt;
0 * * * * /root/rsync_sambanfs.sh&lt;br /&gt;
above cron job run on starting of every hour and take backup &lt;br /&gt;
&lt;br /&gt;
backup is from 10.10.10.15:/data to 10.10.10.25:/data&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
rsync_update_backup&lt;br /&gt;
---------------------&lt;br /&gt;
30 * * * * /root/rsync_update_backup.sh&lt;br /&gt;
above cron job runs on every hour at 30 Minutes&lt;br /&gt;
&lt;br /&gt;
backup from /data to /backup_update_only&lt;br /&gt;
&lt;br /&gt;
You have to delete old /backup_update_only weekly or monthly&lt;br /&gt;
----------&lt;br /&gt;
NFS&lt;br /&gt;
----------&lt;br /&gt;
below command can be used to start/stop NFS service&lt;br /&gt;
/etc/init.d/nfs start&lt;br /&gt;
/etc/init.d/nfs stop&lt;br /&gt;
/etc/init.d/nfs restart&lt;br /&gt;
/etc/init.d/nfs status&lt;br /&gt;
&lt;br /&gt;
use below command to open truecrypt GUI panel&lt;br /&gt;
truecrypt&lt;br /&gt;
&lt;br /&gt;
cronjob -l&lt;br /&gt;
-------------------------&lt;br /&gt;
0 * * * * /root/rsync_sambanfs.sh&lt;br /&gt;
-------------------------&lt;br /&gt;
This cron job take backup from new SambaNFS to old SambaNFS every hour.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Samba==&lt;br /&gt;
&lt;br /&gt;
--------------&lt;br /&gt;
Samba&lt;br /&gt;
--------------&lt;br /&gt;
audit logs can be see by below command&lt;br /&gt;
tail -f /var/log/samba/audit.log&lt;br /&gt;
&lt;br /&gt;
All other logs will be into below directory&lt;br /&gt;
cd /var/log/samba/&lt;br /&gt;
&lt;br /&gt;
samba start/stop commands.&lt;br /&gt;
/etc/init.d/smb status&lt;br /&gt;
/etc/init.d/smb stop&lt;br /&gt;
/etc/init.d/smb restart&lt;br /&gt;
/etc/init.d/smb status&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
There are two nfs mounting. First sambanfs and second is sophosAV &lt;br /&gt;
&lt;br /&gt;
below command will mount the NFS from 10.10.10.15 in /home and /data&lt;br /&gt;
mount -t nfs -o rsize=32768,wsize=32768,timeo=15,tcp   10.10.10.15:/data /data &lt;br /&gt;
mount -t nfs -o rsize=32768,wsize=32768,timeo=15,tcp   10.10.10.15:/home /home&lt;br /&gt;
&lt;br /&gt;
The mounting parameter for sophos is configured into /etc/fstab.&lt;br /&gt;
to mount sophos below command can be used.&lt;br /&gt;
mount -a&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
below commands are for fedora directory server&lt;br /&gt;
/etc/init.d/dirsrv status&lt;br /&gt;
/etc/init.d/dirsrv stop&lt;br /&gt;
/etc/init.d/dirsrv restart&lt;br /&gt;
/etc/init.d/dirsrv status&lt;br /&gt;
&lt;br /&gt;
below commands are for fedora directory server admin console&lt;br /&gt;
/etc/init.d/dirsrv-admin status&lt;br /&gt;
/etc/init.d/dirsrv-admin stop&lt;br /&gt;
/etc/init.d/dirsrv-admin restart&lt;br /&gt;
/etc/init.d/dirsrv-admin status&lt;br /&gt;
&lt;br /&gt;
ldapsearch -x &lt;br /&gt;
will show all the users including their attributes&lt;br /&gt;
&lt;br /&gt;
below command will start the fedora DS admin console.&lt;br /&gt;
389-console &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Second samba 10.10.10.24 starting process&lt;br /&gt;
----------------------------------------&lt;br /&gt;
down first samba 10.10.10.14 (dns1) and login to second samba(dns2) 10.10.10.24 (aditional ip)(the second samba should be up for Fedora DS replication, it&#039;s Fedora DS is read only, no changes directly on it will work)&lt;br /&gt;
&lt;br /&gt;
run below commands on second samba 10.10.10.24&lt;br /&gt;
ifup eth0&lt;br /&gt;
ifup eth0:0&lt;br /&gt;
ifup eth0:1&lt;br /&gt;
ifup eth0:2&lt;br /&gt;
ifup eth0:3&lt;br /&gt;
ifup eth0:4&lt;br /&gt;
ifup eth0:5&lt;br /&gt;
service smb start&lt;br /&gt;
&lt;br /&gt;
above service and ip will be up temporerly, when this machine will reboot this has to do again.&lt;br /&gt;
------------------------------------------&lt;br /&gt;
&lt;br /&gt;
LRS Samba&lt;br /&gt;
------------------------------------------&lt;br /&gt;
10.10.10.28&lt;br /&gt;
57.56.131.200&lt;br /&gt;
samba pdc with ldap&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
below commands are for ldap server&lt;br /&gt;
/etc/init.d/ldap status&lt;br /&gt;
/etc/init.d/ldap stop&lt;br /&gt;
/etc/init.d/ldap restart&lt;br /&gt;
/etc/init.d/ldap status&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
All other logs will be into below directory&lt;br /&gt;
cd /var/log/samba/&lt;br /&gt;
&lt;br /&gt;
samba start/stop commands.&lt;br /&gt;
/etc/init.d/smb status&lt;br /&gt;
/etc/init.d/smb stop&lt;br /&gt;
/etc/init.d/smb restart&lt;br /&gt;
/etc/init.d/smb status&lt;br /&gt;
&lt;br /&gt;
==Sophos Anti Virus ==&lt;br /&gt;
&lt;br /&gt;
------------------------------------------&lt;br /&gt;
Sophos AV&lt;br /&gt;
----------&lt;br /&gt;
start/stop commands.&lt;br /&gt;
&lt;br /&gt;
/etc/init.d/sav-protect start/stop/restart/status&lt;br /&gt;
/etc/init.d/sav-rms start/stop/restart/status &lt;br /&gt;
/etc/init.d/sav-web start/stop/restart/status&lt;br /&gt;
&lt;br /&gt;
WEB GUI url&lt;br /&gt;
&lt;br /&gt;
http://127.0.0.1:8081&lt;br /&gt;
User : sc&lt;br /&gt;
Pass : sc123&lt;br /&gt;
&lt;br /&gt;
Sophos installation path&lt;br /&gt;
&lt;br /&gt;
/opt/sophos-av/&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Sudo Details ==&lt;br /&gt;
&lt;br /&gt;
------&lt;br /&gt;
SUDO&lt;br /&gt;
------&lt;br /&gt;
&lt;br /&gt;
visudo&lt;br /&gt;
-----------------------------&lt;br /&gt;
tetra   ALL=(ALL)       ALL&lt;br /&gt;
vineet  ALL=(ALL)       ALL&lt;br /&gt;
pradeep ALL=(ALL)       ALL&lt;br /&gt;
sunil   ALL=(ALL)       ALL&lt;br /&gt;
&lt;br /&gt;
## Sudo Log&lt;br /&gt;
##Details By Tetra&lt;br /&gt;
Defaults logfile=/var/log/sudo.log&lt;br /&gt;
------------------------------&lt;br /&gt;
&lt;br /&gt;
remote root login disabled as follows.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
vim /etc/ssh/sshd_config&lt;br /&gt;
------------------------------&lt;br /&gt;
chanage&lt;br /&gt;
#PermitRootLogin no&lt;br /&gt;
to&lt;br /&gt;
PermitRootLogin no&lt;br /&gt;
------------------------------&lt;br /&gt;
&lt;br /&gt;
Then restart sshd service.&lt;br /&gt;
&lt;br /&gt;
/etc/init.d/sshd restart&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
tail -f /var/log/sudo.log&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Truecrypt Encryption==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
truecrypt&lt;br /&gt;
------------------&lt;br /&gt;
Truecrypt partition mounting at 10.10.10.28 LRS_Samba&lt;br /&gt;
&lt;br /&gt;
open truecrypt interface select device &amp;quot;/dev/xvda3&amp;quot; &lt;br /&gt;
click mount &lt;br /&gt;
click &amp;quot;options &amp;gt;&amp;quot;&lt;br /&gt;
enter password(tc123), mount directory , and &amp;quot;mount options :&amp;quot; acl&lt;br /&gt;
&lt;br /&gt;
or &lt;br /&gt;
&lt;br /&gt;
command line mount: &lt;br /&gt;
truecrypt -p tc123 /dev/xvda3 /FTPDATA --fs-options=acl --protect-hidden=no --keyfiles= 2&amp;gt;/dev/null&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
command line unmount: &lt;br /&gt;
truecrypt -d /FTPDATA/&lt;br /&gt;
&lt;br /&gt;
==Linux Servers Users ==&lt;br /&gt;
&lt;br /&gt;
--------------------------------&lt;br /&gt;
Linux Servers Users and Password&lt;br /&gt;
--------------------------------&lt;br /&gt;
The root user login on all linux servers is not allowed. To do some administrative work on linux, login with your given user name and use sudo before every admin command to run that command.&lt;br /&gt;
e.g.&lt;br /&gt;
&lt;br /&gt;
sudo tail -f /var/log/qmail/qmail-send/current&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The users are&lt;br /&gt;
&lt;br /&gt;
tetra&lt;br /&gt;
vineet&lt;br /&gt;
pradeep&lt;br /&gt;
sunil&lt;br /&gt;
root - remote login disabled.&lt;br /&gt;
--------------------------------&lt;br /&gt;
&lt;br /&gt;
Sophos AV linux client GUI user and pass for all linux clients&lt;br /&gt;
--------------------------------&lt;br /&gt;
url &lt;br /&gt;
http://127.0.0.1:8081&lt;br /&gt;
&lt;br /&gt;
User : sc&lt;br /&gt;
Pass : sc123&lt;br /&gt;
--------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Fedora DS console Login&lt;br /&gt;
--------------------------------&lt;br /&gt;
389-console&lt;br /&gt;
User : admin&lt;br /&gt;
Pass : ADMIN_rdm23&lt;br /&gt;
--------------------------------&lt;br /&gt;
&lt;br /&gt;
Ossec Web GUI&lt;br /&gt;
--------------------------------&lt;br /&gt;
url &lt;br /&gt;
http://10.10.10.17/ossec&lt;br /&gt;
&lt;br /&gt;
User : admin&lt;br /&gt;
Pass : admin&lt;br /&gt;
--------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Nessus&lt;br /&gt;
--------------------------------&lt;br /&gt;
Installed on Anshu machine&lt;br /&gt;
url https://10.10.10.204:8834&lt;br /&gt;
User : admin&lt;br /&gt;
Pass : admin&lt;br /&gt;
--------------------------------&lt;br /&gt;
&lt;br /&gt;
OSSIM&lt;br /&gt;
--------------------------------&lt;br /&gt;
http://10.10.10.18&lt;br /&gt;
User : admin&lt;br /&gt;
Pass : rdm_sys_0510&lt;br /&gt;
--------------------------------&lt;br /&gt;
--------&lt;br /&gt;
Web&lt;br /&gt;
--------&lt;br /&gt;
http service start/stop commands&lt;br /&gt;
&lt;br /&gt;
/etc/init.d/httpd start&lt;br /&gt;
/etc/init.d/httpd stop&lt;br /&gt;
/etc/init.d/httpd restart&lt;br /&gt;
/etc/init.d/httpd status&lt;br /&gt;
&lt;br /&gt;
html/website pages path&lt;br /&gt;
/var/www/website/&lt;br /&gt;
&lt;br /&gt;
http log files are give below&lt;br /&gt;
tail -f /var/log/httpd/www.rdm.co.in-access_log&lt;br /&gt;
tail -f /var/log/httpd/www.rdm.co.in-error_log&lt;br /&gt;
tail -f /var/log/httpd/www.rdmfamily.in-error_log&lt;br /&gt;
tail -f /var/log/httpd/www.rdmfamily.in-access_log&lt;br /&gt;
tail -f /var/log/messages&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==FTP==&lt;br /&gt;
&lt;br /&gt;
--------&lt;br /&gt;
FTP&lt;br /&gt;
--------&lt;br /&gt;
ftp service start/stop commands&lt;br /&gt;
&lt;br /&gt;
/etc/init.d/vsftpd start&lt;br /&gt;
/etc/init.d/vsftpd stop&lt;br /&gt;
/etc/init.d/vsftpd restart&lt;br /&gt;
/etc/init.d/vsftpd status&lt;br /&gt;
&lt;br /&gt;
ftp log file&lt;br /&gt;
tail -f /var/log/messages&lt;br /&gt;
&lt;br /&gt;
FTP users are&lt;br /&gt;
--------------------------------&lt;br /&gt;
User		home direcotry&lt;br /&gt;
--------------------------------&lt;br /&gt;
logistics	/var/www/website/rdmfamily/Routes&lt;br /&gt;
hr		/var/www/website/rdmfamily&lt;br /&gt;
admin		/var/www/website&lt;br /&gt;
&lt;br /&gt;
to change ftp users password run below command&lt;br /&gt;
passwd logistics&lt;br /&gt;
passwd hr &lt;br /&gt;
passwd admin&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Webmin==&lt;br /&gt;
&lt;br /&gt;
--------------&lt;br /&gt;
Webmin is installed on all Linux servers&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
URL access&lt;br /&gt;
http://ip:10000&lt;br /&gt;
&lt;br /&gt;
User : root&lt;br /&gt;
Pass : &amp;lt;rootpass&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==XEN Services==&lt;br /&gt;
&lt;br /&gt;
------------------------------------------&lt;br /&gt;
XEN services/vm status/start/stop commands&lt;br /&gt;
------------------------------------------&lt;br /&gt;
&lt;br /&gt;
To start and stop use below xen commands&lt;br /&gt;
&lt;br /&gt;
/etc/init.d/xend status&lt;br /&gt;
/etc/init.d/xend start&lt;br /&gt;
/etc/init.d/xend stop&lt;br /&gt;
/etc/init.d/xend restart&lt;br /&gt;
&lt;br /&gt;
/etc/init.d/xendomains status&lt;br /&gt;
/etc/init.d/xendomains start&lt;br /&gt;
/etc/init.d/xendomains stop&lt;br /&gt;
/etc/init.d/xendomains restart&lt;br /&gt;
&lt;br /&gt;
below command will list running virtual machines.&lt;br /&gt;
xm list&lt;br /&gt;
&lt;br /&gt;
below command will start the qmail from the command line.&lt;br /&gt;
&lt;br /&gt;
xm create qmail &lt;br /&gt;
&lt;br /&gt;
below command will open virt-manager to see virtual machines.&lt;br /&gt;
virt-manager -- will open GUI&lt;/div&gt;</summary>
		<author><name>Shashanksharma</name></author>
	</entry>
	<entry>
		<id>https://wiki.tetrain.com/index.php?title=Zimbra_logo_change&amp;diff=1567</id>
		<title>Zimbra logo change</title>
		<link rel="alternate" type="text/html" href="https://wiki.tetrain.com/index.php?title=Zimbra_logo_change&amp;diff=1567"/>
		<updated>2014-02-12T07:19:39Z</updated>

		<summary type="html">&lt;p&gt;Shashanksharma: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Category:Zimbra]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; == Changing Logo for the second Domain besmech.com ( [[Virtual Domain on Zimbra]] ) for witalsee zimbra server == &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
 su - zimbra&lt;br /&gt;
 mkdir /opt/zimbra/jetty/webapps/zimbra/skins/logos&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Create two logos of pixels :- 459x218(LoginBanner.png) &amp;amp; 74x35(AppBanner.png)&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;move the images in the directory /opt/zimbra/jetty/webapps/zimbra/skins/logos/&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
 chown zimbra.zimbra AppBanner.png&lt;br /&gt;
 chown zimbra.zimbra LoginBanner.png&lt;br /&gt;
 zmprov modifyDomain besmech.com zimbraSkinLogoLoginBanner /zimbra/skins/logos/LoginBanner.png&lt;br /&gt;
 zmprov modifyDomain besmech.com zimbraSkinLogoAppBanner /zimbra/skins/logos/AppBanner.png&lt;br /&gt;
 zmmailboxdctl restart&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Open mail.besmech.com to confirm (Clear browser cache/cookies)&#039;&#039;&#039;&lt;/div&gt;</summary>
		<author><name>Shashanksharma</name></author>
	</entry>
	<entry>
		<id>https://wiki.tetrain.com/index.php?title=Main_Page/Add_rules_in_spamassasin_for_spam_tagging&amp;diff=1562</id>
		<title>Main Page/Add rules in spamassasin for spam tagging</title>
		<link rel="alternate" type="text/html" href="https://wiki.tetrain.com/index.php?title=Main_Page/Add_rules_in_spamassasin_for_spam_tagging&amp;diff=1562"/>
		<updated>2014-02-06T05:15:31Z</updated>

		<summary type="html">&lt;p&gt;Shashanksharma: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[category:Qmail]]&lt;br /&gt;
[[category:Zimbra]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Word of Caution for this document as document not approved - Biswajit Banerjee ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== To reduce spam we need to add rules in spamassassin ==&lt;br /&gt;
&lt;br /&gt;
This can be achieve by tuning spamassassin and applying / adding rules for effective spam filtering. &lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
For some cases only whitelisting and blacklisting of domain does not help . hence we need custom rules for such cases. &lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== where to write the rules : ==&lt;br /&gt;
 &lt;br /&gt;
/etc/mail/spamassassin/local.cf&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Writing basic rules ==&lt;br /&gt;
&lt;br /&gt;
== Body rules : ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These rules search the body of the message with a regular expression and if it matches, the corresponding score is assigned. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
body EXAMPLE_RULE /test/&lt;br /&gt;
score EXAMPLE_RULE 0.1&lt;br /&gt;
describe EXAMPLE_RULE This is a simple test rule &lt;br /&gt;
&lt;br /&gt;
This rule does a simple case-sensitive search of the body of the email for the string &amp;quot;test&amp;quot; and adds a 0.1 to the score of the email if it finds it&lt;br /&gt;
It will match &amp;quot;test&amp;quot; but also &amp;quot;testing&amp;quot; and &amp;quot;attest&amp;quot;&lt;br /&gt;
In regular expressions a \b can be used to indicate where a word-break (anything that isn&#039;t an alphanumeric character or underscore) must exist for a match. Our rule above can be made to not match &amp;quot;testing&amp;quot; or &amp;quot;attest&amp;quot; like so:&lt;br /&gt;
&lt;br /&gt;
body EXAMPLE_RULE /\btest\b/ &lt;br /&gt;
&lt;br /&gt;
The rule can also be made case-insensitive by adding an i to the end, like this:&lt;br /&gt;
&lt;br /&gt;
body EXAMPLE_RULE /\btest\b/i&lt;br /&gt;
score EXAMPLE_RULE 0.1&lt;br /&gt;
&lt;br /&gt;
Now the rule will match any combination of upper or lower case that spells &amp;quot;test&amp;quot; surrounded by word breaks of some form. &lt;br /&gt;
&lt;br /&gt;
== Header rules ==&lt;br /&gt;
&lt;br /&gt;
Header rules let you check a message header for a string. Most commonly these rules check the Subject, From, or To, but they can be written to check any message header, including non-standard ones&lt;br /&gt;
fOR SUBJECT RULES :&lt;br /&gt;
header EXAMPLE_SUBJECT Subject =~ /\btest\b/i&lt;br /&gt;
score EXAMPLE_SUBJECT 0.1 &lt;br /&gt;
&lt;br /&gt;
The above rule will match a subject: line containing &amp;quot;test&amp;quot; or a SUBJECT: line containing &amp;quot;test&amp;quot;. The first part before the =~ indicates what the name of the header you want to check &lt;br /&gt;
&lt;br /&gt;
Checking the From: line, or any other header, works much the same:&lt;br /&gt;
&lt;br /&gt;
header EXAMPLE_FROM From =~ /test\.com/i&lt;br /&gt;
score EXAMPLE_FROM 0.1 &lt;br /&gt;
&lt;br /&gt;
== THERE WAS A CASE WHERE SPAM USED TO COME FROM DIFFRENT DOMAINS OF SIMILAR NAME ( MYJAMANA 1 , MYJAMAN2, MYJAMANA3, MYJAMANA4 ETC.) FOR THIS THE FROM RULE IS APPLICABLE  ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
There&#039;s also an option to look at all the headers and match if any of them contain the specified regex:&lt;br /&gt;
&lt;br /&gt;
header LOCAL_DEMONSTRATION_ALL ALL =~ /test\.com/i&lt;br /&gt;
score LOCAL_DEMONSTRATION_ALL 0.1&lt;br /&gt;
&lt;br /&gt;
Not very commonly used, but this feature can also be used to do a case-sensitive check on a header name (it will look at the whole lines, not just the parts after the colon)&lt;br /&gt;
&lt;br /&gt;
header LOCAL_DEMONSTRATION_WEIRD_FROM ALL =~ /^FrOM\:/ &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== A few short words about the behavior of the &amp;quot;score&amp;quot; command  ==&lt;br /&gt;
    - rules with a score set to 0 are not evaluated at all.&lt;br /&gt;
    - rules with no score statement will be scored at 1.0, unless 3 or 4 is true&lt;br /&gt;
    - rules starting with a double __ are evaluated with no score, and are intended for use in meta rules where you don&#039;t&lt;br /&gt;
      want the sub-rules to have a score.&lt;br /&gt;
    - although intended for the sa development effort, any rule starting with T_ will be treated as a &amp;quot;test&amp;quot; rule and will &lt;br /&gt;
      be run with a score of 0.01 (nearly 0). This can be handy when testing rules so you don&#039;t have to create score lines &lt;br /&gt;
      for them if you think you&#039;re not going to keep them.&lt;/div&gt;</summary>
		<author><name>Shashanksharma</name></author>
	</entry>
	<entry>
		<id>https://wiki.tetrain.com/index.php?title=Malware_Issue&amp;diff=1560</id>
		<title>Malware Issue</title>
		<link rel="alternate" type="text/html" href="https://wiki.tetrain.com/index.php?title=Malware_Issue&amp;diff=1560"/>
		<updated>2014-01-24T07:54:38Z</updated>

		<summary type="html">&lt;p&gt;Shashanksharma: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Category:Zimbra]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Malware Issue faced and rectified on Linux Mail Servers&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Symtoms&lt;br /&gt;
   1) Load will gradually rise.&lt;br /&gt;
   2) CPU Utilization will rise.&lt;br /&gt;
   3) Both became stable at a level(around 20 load)&lt;br /&gt;
   4) Wierd applications would found running when you monitor TOP. &lt;br /&gt;
&lt;br /&gt;
Steps to find out the location of malware&lt;br /&gt;
   1) Monitor cpu usage using TOP command&lt;br /&gt;
   2) Any service which is using CPU around 200% , monitor that service. &lt;br /&gt;
   3) Using ps -elf | grep &amp;quot;--service name--&amp;quot;   , find out wether the service is genuine or froud. &lt;br /&gt;
   4) Find out the location of that malware. (Basically it is found in tmp directory - /tmp , /usr/tmp , /var/tmp  or at /root/ or / ) &lt;br /&gt;
   &lt;br /&gt;
Steps to secure our machine&lt;br /&gt;
   1) First of all kill that process using its PROCESS ID( mind that you use its PID)&lt;br /&gt;
   2) As if you delete the malware, it will be regenarated. So you have to clean that file and make sure it won&#039;t regenerate. &lt;br /&gt;
   3) Then echo &amp;gt; --malware--  ( empty the contents of malware fle)&lt;br /&gt;
   4) Then chmod 000 --malware-- &lt;br /&gt;
   5) Then chattr +i --malware-- (apply chattr so that it the malware could be created again,hence system is secured)&lt;br /&gt;
      ***(--malware-- has to be replaced with the name of malware present on the server, ex. meep.pl , a , b , etc.)&lt;br /&gt;
&lt;br /&gt;
Usual location of these malwares &lt;br /&gt;
   1) /tmp&lt;br /&gt;
   2) /var/tmp   --80% of times malware is found here. &lt;br /&gt;
   3) /usr/tmp&lt;br /&gt;
   4) /root/     --hidden file would be found here ( like .kpoll ) &lt;br /&gt;
   5) /          --hidden file would be found here&lt;br /&gt;
&lt;br /&gt;
Victims &lt;br /&gt;
   1) Systems with high end configuration (All mail servers, Basically Zimbra ones because of their high configuration)&lt;br /&gt;
   2) Systems with high clock frequency/ RAM/ Dedicated Graphic Card (Nvidia/AMD Radion)&lt;br /&gt;
   3) Systems with great uptime&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;For help - malware are basically of names like - a,b,meep.sh,xd.pl,minerd,minerd32,minerd64,kpoll,fuss. and are found 80% of times at /var/tmp/&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
For more details you can visit -&amp;gt; http://goo.gl/eOcSsn&lt;/div&gt;</summary>
		<author><name>Shashanksharma</name></author>
	</entry>
	<entry>
		<id>https://wiki.tetrain.com/index.php?title=Malware_Issue&amp;diff=1559</id>
		<title>Malware Issue</title>
		<link rel="alternate" type="text/html" href="https://wiki.tetrain.com/index.php?title=Malware_Issue&amp;diff=1559"/>
		<updated>2014-01-24T07:42:05Z</updated>

		<summary type="html">&lt;p&gt;Shashanksharma: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Category:Zimbra]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Malware Issue faced and rectified on Linux Mail Servers&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Symtoms&lt;br /&gt;
   1) Load will gradually rise.&lt;br /&gt;
   2) CPU Utilization will rise.&lt;br /&gt;
   3) Both became stable at a level(around 20 load)&lt;br /&gt;
   4) Wierd applications would found running when you monitor TOP. &lt;br /&gt;
&lt;br /&gt;
Steps to find out the location of malware&lt;br /&gt;
   1) Monitor cpu usage using TOP command&lt;br /&gt;
   2) Any service which is using CPU around 200% , monitor that service. &lt;br /&gt;
   3) Using ps -elf | grep &amp;quot;--service name--&amp;quot;   , find out wether the service is genuine or froud. &lt;br /&gt;
   4) Find out the location of that malware. (Basically it is found in tmp directory - /tmp , /usr/tmp , /var/tmp  or at /root/ or / ) &lt;br /&gt;
   &lt;br /&gt;
Steps to secure our machine&lt;br /&gt;
   1) First of all kill that process using its PROCESS ID( mind that you use its PID)&lt;br /&gt;
   2) As if you delete the malware, it will be regenarated. So you have to clean that file and make sure it won&#039;t regenerate. &lt;br /&gt;
   3) Then echo &amp;gt; --malware--  ( empty the contents of malware fle)&lt;br /&gt;
   4) Then chmod 000 --malware-- &lt;br /&gt;
   5) Then chattr +i --malware-- (apply chattr so that it the malware could be created again,hence system is secured)&lt;br /&gt;
&lt;br /&gt;
Usual location of these malwares &lt;br /&gt;
   1) /tmp&lt;br /&gt;
   2) /var/tmp   --80% of times malware is found here. &lt;br /&gt;
   3) /usr/tmp&lt;br /&gt;
   4) /root/     --hidden file would be found here ( like .kpoll ) &lt;br /&gt;
   5) /          --hidden file would be found here&lt;br /&gt;
&lt;br /&gt;
Victims &lt;br /&gt;
   1) Systems with high end configuration (All mail servers, Basically Zimbra ones because of their high configuration)&lt;br /&gt;
   2) Systems with high clock frequency/ RAM/ Dedicated Graphic Card (Nvidia/AMD Radion)&lt;br /&gt;
   3) Systems with great uptime&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;For help - malware are basically of names like - a,b,meep.sh,xd.pl,minerd,minerd32,minerd64,kpoll,fuss. and are found 80% of times at /var/tmp/&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
For more details you can visit -&amp;gt; http://goo.gl/eOcSsn&lt;/div&gt;</summary>
		<author><name>Shashanksharma</name></author>
	</entry>
	<entry>
		<id>https://wiki.tetrain.com/index.php?title=Malware_Issue&amp;diff=1556</id>
		<title>Malware Issue</title>
		<link rel="alternate" type="text/html" href="https://wiki.tetrain.com/index.php?title=Malware_Issue&amp;diff=1556"/>
		<updated>2014-01-24T06:38:34Z</updated>

		<summary type="html">&lt;p&gt;Shashanksharma: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Category:Zimbra]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Malware Issue faced and rectified on Linux Mail Servers&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Symtoms&lt;br /&gt;
   1) Load will gradually rise.&lt;br /&gt;
   2) CPU Utilization will rise.&lt;br /&gt;
   3) Both became stable at a level(around 20 load)&lt;br /&gt;
   4) Wierd applications would found running when you monitor TOP. &lt;br /&gt;
&lt;br /&gt;
Steps to find out the location of malware&lt;br /&gt;
   1) Monitor cpu usage using TOP command&lt;br /&gt;
   2) Any service which is using CPU around 200% , monitor that service. &lt;br /&gt;
   3) Using ps -elf | grep &amp;quot;--service name--&amp;quot;   , find out wether the service is genuine or froud. &lt;br /&gt;
   4) Find out the location of that malware. (Basically it is found in tmp directory - /tmp , /usr/tmp , /var/tmp  or at /root/ or / ) &lt;br /&gt;
   &lt;br /&gt;
Steps to secure our machine&lt;br /&gt;
   1) First of all kill that process using its PROCESS ID( mind that you use its PID)&lt;br /&gt;
   2) As if you delete the malware, it will be regenarated. So you have to clean that file and make sure it won&#039;t regenerate. &lt;br /&gt;
   3) Then echo &amp;gt; --malware--  ( empty the contents of malware fle)&lt;br /&gt;
   4) Then chmod 000 --malware-- &lt;br /&gt;
   5) Then chattr +i --malware-- (apply chattr so that it the malware could be created again,hence system is secured)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;For help - malware are basically of names like - a,b,meep.sh,xd.pl,minerd,minerd32,minerd64,kpoll,fuss. and are found 80% of times at /var/tmp/&#039;&#039;&lt;/div&gt;</summary>
		<author><name>Shashanksharma</name></author>
	</entry>
	<entry>
		<id>https://wiki.tetrain.com/index.php?title=Malware_Issue&amp;diff=1555</id>
		<title>Malware Issue</title>
		<link rel="alternate" type="text/html" href="https://wiki.tetrain.com/index.php?title=Malware_Issue&amp;diff=1555"/>
		<updated>2014-01-24T06:37:35Z</updated>

		<summary type="html">&lt;p&gt;Shashanksharma: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Category:Zimbra]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Malware Issue faced and rectified on Linux Mail Servers&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
[[Symtoms]]&lt;br /&gt;
   1) Load will gradually rise.&lt;br /&gt;
   2) CPU Utilization will rise.&lt;br /&gt;
   3) Both became stable at a level(around 20 load)&lt;br /&gt;
   4) Wierd applications would found running when you monitor TOP. &lt;br /&gt;
&lt;br /&gt;
[[Steps to find out the location of malware]] &lt;br /&gt;
   1) Monitor cpu usage using TOP command&lt;br /&gt;
   2) Any service which is using CPU around 200% , monitor that service. &lt;br /&gt;
   3) Using ps -elf | grep &amp;quot;--service name--&amp;quot;   , find out wether the service is genuine or froud. &lt;br /&gt;
   4) Find out the location of that malware. (Basically it is found in tmp directory - /tmp , /usr/tmp , /var/tmp  or at /root/ or / ) &lt;br /&gt;
   &lt;br /&gt;
[[Steps to secure our machine]]&lt;br /&gt;
   1) First of all kill that process using its PROCESS ID( mind that you use its PID)&lt;br /&gt;
   2) As if you delete the malware, it will be regenarated. So you have to clean that file and make sure it won&#039;t regenerate. &lt;br /&gt;
   3) Then echo &amp;gt; --malware--  ( empty the contents of malware fle)&lt;br /&gt;
   4) Then chmod 000 --malware-- &lt;br /&gt;
   5) Then chattr +i --malware-- (apply chattr so that it the malware could be created again,hence system is secured)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;For help - malware are basically of names like - a,b,meep.sh,xd.pl,minerd,minerd32,minerd64,kpoll,fuss. and are found 80% of times at /var/tmp/&#039;&#039;&lt;/div&gt;</summary>
		<author><name>Shashanksharma</name></author>
	</entry>
	<entry>
		<id>https://wiki.tetrain.com/index.php?title=Malware_Issue&amp;diff=1554</id>
		<title>Malware Issue</title>
		<link rel="alternate" type="text/html" href="https://wiki.tetrain.com/index.php?title=Malware_Issue&amp;diff=1554"/>
		<updated>2014-01-24T06:35:23Z</updated>

		<summary type="html">&lt;p&gt;Shashanksharma: Created page with &amp;quot;Category:Zimbra  &amp;#039;&amp;#039;&amp;#039;Malware Issue faced and rectified on Linux Mail Servers&amp;#039;&amp;#039;&amp;#039;  Symtoms     1) Load will gradually rise.    2) CPU Utilization will rise.    3) Bot...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Category:Zimbra]]&lt;br /&gt;
&lt;br /&gt;
[[&#039;&#039;&#039;Malware Issue faced and rectified on Linux Mail Servers&#039;&#039;&#039;]]&lt;br /&gt;
&lt;br /&gt;
[[Symtoms]] &lt;br /&gt;
   1) Load will gradually rise.&lt;br /&gt;
   2) CPU Utilization will rise.&lt;br /&gt;
   3) Both became stable at a level(around 20 load)&lt;br /&gt;
   4) Wierd applications would found running when you monitor TOP. &lt;br /&gt;
&lt;br /&gt;
[[Steps to find out the location of malware]] &lt;br /&gt;
   1) Monitor cpu usage using TOP command&lt;br /&gt;
   2) Any service which is using CPU around 200% , monitor that service. &lt;br /&gt;
   3) Using ps -elf | grep &amp;quot;--service name--&amp;quot;   , find out wether the service is genuine or froud. &lt;br /&gt;
   4) Find out the location of that malware. (Basically it is found in tmp directory - /tmp , /usr/tmp , /var/tmp  or at /root/ or / ) &lt;br /&gt;
   &lt;br /&gt;
[[Steps to secure our machine]] &lt;br /&gt;
   1) First of all kill that process using its PROCESS ID( mind that you use its PID)&lt;br /&gt;
   2) As if you delete the malware, it will be regenarated. So you have to clean that file and make sure it won&#039;t regenerate. &lt;br /&gt;
   3) Then echo &amp;gt; --malware--  ( empty the contents of malware fle)&lt;br /&gt;
   4) Then chmod 000 --malware-- &lt;br /&gt;
   5) Then chattr +i --malware-- (apply chattr so that it the malware could be created again,hence system is secured)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;For help - malware are basically of names like - a,b,meep.sh,xd.pl,minerd,minerd32,minerd64,kpoll,fuss. and are found 80% of times at /var/tmp/&#039;&#039;&lt;/div&gt;</summary>
		<author><name>Shashanksharma</name></author>
	</entry>
	<entry>
		<id>https://wiki.tetrain.com/index.php?title=Mahuaa_cluster_issue&amp;diff=1516</id>
		<title>Mahuaa cluster issue</title>
		<link rel="alternate" type="text/html" href="https://wiki.tetrain.com/index.php?title=Mahuaa_cluster_issue&amp;diff=1516"/>
		<updated>2013-12-03T07:14:53Z</updated>

		<summary type="html">&lt;p&gt;Shashanksharma: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;  Scenerio : &lt;br /&gt;
      There are two nodes (mail.mahuaatv.com &amp;amp; mail1.mahuaatv.com) of cluster running at Mahuaa. Basically what happened was that &lt;br /&gt;
      mail1.mahuaatv.com stopped working. Neither approachable via ping nor by ssh. &lt;br /&gt;
&lt;br /&gt;
  What We Did To Resue the Issue : &lt;br /&gt;
  &amp;gt;  Shutted down both the systems. &lt;br /&gt;
  &amp;gt;  Node 1 was brought up. &lt;br /&gt;
  &amp;gt;  After proper startup of node 1, node 2 was brought up.&lt;br /&gt;
  &amp;gt;  Here we face an issue that node 1 was not coming up and stuck at boot process. Issue was regarding the disk issue. &lt;br /&gt;
  &amp;gt;  Then finally after 2-3 tries, We removed lan cable &amp;amp; it automatically started.&lt;br /&gt;
  &amp;gt;  Both machines were up but neither if them was in network(i.e. not accessible via global ip)&lt;br /&gt;
  &amp;gt;  Then machine was brought in local n/w and it was accessed via taking teamviewer of a local machine and through that machine to server.&lt;br /&gt;
  &amp;gt;  Then following was done on server  :&lt;br /&gt;
&lt;br /&gt;
On Node 2 :&lt;br /&gt;
&lt;br /&gt;
  /etc/init.d/heartbeat stop&lt;br /&gt;
  Stopped heartbeat&lt;br /&gt;
&lt;br /&gt;
  tailf /var/log/ha-log&lt;br /&gt;
  checked logs wether the heartbeat is properly shutting down or not&lt;br /&gt;
&lt;br /&gt;
  cat /proc/drbd&lt;br /&gt;
  checked wether this machine is now secondary or not.&lt;br /&gt;
&lt;br /&gt;
  df -h&lt;br /&gt;
  checked wether the /home is unmounted or not. &lt;br /&gt;
&lt;br /&gt;
now to Node 1 :&lt;br /&gt;
  &lt;br /&gt;
  /etc/init.d/heartbeat stop&lt;br /&gt;
  /etc/init.d/heartbeat start&lt;br /&gt;
  restart the service &lt;br /&gt;
&lt;br /&gt;
  tail -f /var/log/ha-log&lt;br /&gt;
  checked the logs wether the heartbeat is properly started or not. &lt;br /&gt;
&lt;br /&gt;
  cat /proc/drbd &lt;br /&gt;
  check wether the server is primary or not.&lt;br /&gt;
&lt;br /&gt;
  cat /etc/ha.d/haresources &lt;br /&gt;
  in this file we check what ip has to be assigned to node 1 , what services to be started, which partition to be mounter and where.&lt;br /&gt;
&lt;br /&gt;
  now check ip address &lt;br /&gt;
  ifconfig &lt;br /&gt;
   &lt;br /&gt;
  Check wether the /home partition is mounted or not.&lt;br /&gt;
  df-h&lt;br /&gt;
&lt;br /&gt;
now check wether all the services are up or not which are defined in /etc/ha.d/haresources /etc/ha.d/haresources file.&lt;br /&gt;
&lt;br /&gt;
example :  &lt;br /&gt;
 [root@mail ~]# cat /etc/ha.d/haresources&lt;br /&gt;
 mail.mahuaatv.com  IPaddr::193.168.0.222/24/eth1 drbddisk::r0 Filesystem::/dev/drbd0::/home::ext3 mysqld dovecot clam_permissions clamd amavisd  postfix httpd crond&lt;br /&gt;
&lt;br /&gt;
 [root@mail ~]# /etc/init.d/mysqld status &lt;br /&gt;
 mysqld (pid 24486) is running... &lt;br /&gt;
&lt;br /&gt;
 [root@mail ~]# /etc/init.d/dovecot status &lt;br /&gt;
 dovecot (pid  24536) is running... &lt;br /&gt;
&lt;br /&gt;
 [root@mail ~]# /etc/init.d/clamd status &lt;br /&gt;
 clamd (pid 24617) is running... &lt;br /&gt;
&lt;br /&gt;
 [root@mail ~]# /etc/init.d/amavisd status &lt;br /&gt;
 amavisd (pid 25009 25008 25006 25004 25003 25002 25001 25000 24999 24998 24660) is running... &lt;br /&gt;
 amavis-milter is stopped &lt;br /&gt;
&lt;br /&gt;
 [root@mail ~]# /etc/init.d/postfix status &lt;br /&gt;
 master (pid 24743) is running... &lt;br /&gt;
&lt;br /&gt;
 [root@mail ~]# /etc/init.d/httpd  status &lt;br /&gt;
 httpd (pid  24785) is running... &lt;br /&gt;
&lt;br /&gt;
 [root@mail ~]# /etc/init.d/crond status &lt;br /&gt;
 crond (pid  24823) is running... &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
now check wether the node is primary and is uptodate :&lt;br /&gt;
&lt;br /&gt;
 [root@mail ~]# cat /proc/drbd&lt;br /&gt;
 version: 8.0.16 (api:86/proto:86)&lt;br /&gt;
 GIT-hash: d30881451c988619e243d6294a899139eed1183d build by mockbuild@v20z-x86-64.home.local, 2009-08-22 13:23:56&lt;br /&gt;
 0: cs:Connected st:Primary/Secondary ds:UpToDate/UpToDate C r---&lt;br /&gt;
 ns:30232760 nr:8 dw:29180096 dr:2144235 al:35473 bm:787 lo:0 pe:0 ua:0 ap:0&lt;br /&gt;
 resync: used:0/61 hits:0 misses:0 starving:0 dirty:0 changed:0&lt;br /&gt;
 act_log: used:0/257 hits:7259549 misses:36475 starving:0 dirty:1002 changed:35473&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
---DONE---&lt;/div&gt;</summary>
		<author><name>Shashanksharma</name></author>
	</entry>
	<entry>
		<id>https://wiki.tetrain.com/index.php?title=Monitoring_Incoming_%26_outgoing_mails_in_zimbra&amp;diff=1431</id>
		<title>Monitoring Incoming &amp; outgoing mails in zimbra</title>
		<link rel="alternate" type="text/html" href="https://wiki.tetrain.com/index.php?title=Monitoring_Incoming_%26_outgoing_mails_in_zimbra&amp;diff=1431"/>
		<updated>2013-09-23T12:51:14Z</updated>

		<summary type="html">&lt;p&gt;Shashanksharma: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
  Here is how to configure a particular mail id to hold a record of all either incoming,or outgoing mails from a particular server or a particular email &lt;br /&gt;
  id in Zimbra.&lt;br /&gt;
&lt;br /&gt;
  Source -&amp;gt; http://www.postfix.org/ADDRESS_REWRITING_README.html#auto_bcc&lt;br /&gt;
         -&amp;gt; http://www.zimbra.com/forums/administrators/28958-solved-sender_bcc_maps-not-receiving-mail-lt.html    &lt;br /&gt;
&lt;br /&gt;
  Changes in /etc/postfix/main.cf :&lt;br /&gt;
  #Add following line to get a bcc copy to your email id when some one send a mail:&lt;br /&gt;
    sender_bcc_maps = hash:/etc/sender_bcc&lt;br /&gt;
  #Add following line to get a bcc copy to your email id when some one receive a mail:&lt;br /&gt;
    recipient_bcc_maps = hash:/etc/recipient_bcc&lt;br /&gt;
  :wq!&lt;br /&gt;
&lt;br /&gt;
  # vim /etc/sender_bcc&lt;br /&gt;
    @domain.com outgoing@domain.com                  #to get sent mails of whole server&lt;br /&gt;
    user@domain.com user_outgoing@domain.com         #to get sent mails of particular user&lt;br /&gt;
&lt;br /&gt;
  # vim /etc/recipient_bcc&lt;br /&gt;
    @domain.com imcoming@domain.com                  #to get received mails of whole server&lt;br /&gt;
    user@domain.com user_incoming@domain.com         #to get received mails of particular user&lt;br /&gt;
&lt;br /&gt;
  Now run the following commands&lt;br /&gt;
  # /opt/zimbra/postfix/sbin/postmap /etc/sender_bcc&lt;br /&gt;
  # /opt/zimbra/postfix/sbin/postmap /etc/recipient_bcc&lt;br /&gt;
  # /opt/zimbra/postfix/sbin/postfix reload &lt;br /&gt;
&lt;br /&gt;
---DONE---&lt;br /&gt;
Working fine on TIPL**&lt;/div&gt;</summary>
		<author><name>Shashanksharma</name></author>
	</entry>
	<entry>
		<id>https://wiki.tetrain.com/index.php?title=Monitoring_Incoming_%26_outgoing_mails_in_zimbra&amp;diff=1430</id>
		<title>Monitoring Incoming &amp; outgoing mails in zimbra</title>
		<link rel="alternate" type="text/html" href="https://wiki.tetrain.com/index.php?title=Monitoring_Incoming_%26_outgoing_mails_in_zimbra&amp;diff=1430"/>
		<updated>2013-09-23T11:49:43Z</updated>

		<summary type="html">&lt;p&gt;Shashanksharma: Created page with &amp;quot;   Here is how to configure a particular mail id to hold a record of all either incoming,or outgoing mails from a particular server or a particular email    id in Zimbra.    C...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
  Here is how to configure a particular mail id to hold a record of all either incoming,or outgoing mails from a particular server or a particular email &lt;br /&gt;
  id in Zimbra.&lt;br /&gt;
&lt;br /&gt;
  Changes in /etc/postfix/main.cf :&lt;br /&gt;
  #Add following line to get a bcc copy to your email id when some one send a mail:&lt;br /&gt;
    sender_bcc_maps = hash:/etc/sender_bcc&lt;br /&gt;
  #Add following line to get a bcc copy to your email id when some one receive a mail:&lt;br /&gt;
    recipient_bcc_maps = hash:/etc/recipient_bcc&lt;br /&gt;
  :wq!&lt;br /&gt;
&lt;br /&gt;
  # vim /etc/sender_bcc&lt;br /&gt;
    @domain.com outgoing@domain.com                  #to get sent mails of whole server&lt;br /&gt;
    user@domain.com user_outgoing@domain.com         #to get sent mails of particular user&lt;br /&gt;
&lt;br /&gt;
  # vim /etc/recipient_bcc&lt;br /&gt;
    @domain.com imcoming@domain.com                  #to get received mails of whole server&lt;br /&gt;
    user@domain.com user_incoming@domain.com         #to get received mails of particular user&lt;br /&gt;
&lt;br /&gt;
  Now run the following commands&lt;br /&gt;
  # /opt/zimbra/postfix/sbin/postmap /etc/sender_bcc&lt;br /&gt;
  # /opt/zimbra/postfix/sbin/postmap /etc/recipient_bcc&lt;br /&gt;
  # /opt/zimbra/postfix/sbin/postfix reload &lt;br /&gt;
&lt;br /&gt;
---DONE---&lt;br /&gt;
Working fine on TIPL**&lt;/div&gt;</summary>
		<author><name>Shashanksharma</name></author>
	</entry>
</feed>