Is there a way I can configure the following log entry for Clamav-milter to also output the origin address? The reason I'm asking is because I'm using a script to go through the log file and count all of the big virus senders but it takes forever to run since I'm having to loop through my maillog file to find the message id "i79K3CfR009900" with the ip address.
So I see this.... Aug 9 16:03:14 ns2b clamav-milter[9851]: i79K3CfR009900: stream: Trojan.JS.RunMeIntercepted virus from <[EMAIL PROTECTED]> to <[EMAIL PROTECTED]> But would like to see something similar to this...(if possible) Aug 9 16:03:14 ns2b clamav-milter[9851]: i79K3CfR009900: stream: Trojan.JS.RunMeIntercepted virus from <[EMAIL PROTECTED]> at 4.4.103.77 to <[EMAIL PROTECTED]> Thanks, Brett ------------------------------------------------------- SF.Net email is sponsored by Shop4tech.com-Lowest price on Blank Media 100pk Sonic DVD-R 4x for only $29 -100pk Sonic DVD+R for only $33 Save 50% off Retail on Ink & Toner - Free Shipping and Free Gift. http://www.shop4tech.com/z/Inkjet_Cartridges/9_108_r285 _______________________________________________ Clamav-users mailing list [EMAIL PROTECTED] https://lists.sourceforge.net/lists/listinfo/clamav-users