We have had a bad week with hammer attacks on our pop3 and webmail. We have locked that down but it appears at least one account has been compromised. We see traffic in the outmail log that shows mail being sent, but need to identify what account is sending it. Is there any easy way, without enabling debug mode in logging. In debug mode re rapidly get overloaded with huge log files.
Maybe the better way to ask is this--> If we feel that an account has been exploited - either by virus or poor password, whats the easiest way to check which accounts are sending which mail - we have a couple hundred accounts on about 30 domains.