Postfix SMTP Submission Syslog
Postfix 3.8.3+ submission-relay messages from smtpd, cleanup, qmgr and smtp as parsed ECS JSON with the native syslog line in event.original, for testing mail-server authentication and outbound-mail detections. About 54,700 records and 10,100 messages a day from 150 staff users on a UTC working-day curve and eight application accounts around the clock; every accepted submission is followed from queue creation to removal. Recurring episodes show one staff user failing SASL LOGIN three times, then submitting a message for five external recipients.
Quick Start
uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
--path generators/email-postfix/generator.yml \
--id email-postfix \
--live-mode trueEvent Types
| Event ID | Description | Frequency | Category |
|---|---|---|---|
| postfix/smtpd client= sasl_username= | Queue ID assigned to an authenticated submission (client, sasl_method=LOGIN, sasl_username) | 18.5% of records | |
| postfix/cleanup message-id= | Message-ID of the queued message | 18.5% of records | |
| postfix/qmgr queue active | Sender, size and recipient count on queue activation | 18.5% of records | |
| postfix/smtp status=sent | Delivery of one recipient to an external relay with delay, delays and dsn=2.0.0 | 25.3% of records, one per recipient | |
| postfix/qmgr removed | Queue entry removed after all deliveries | 18.5% of records | |
| postfix/smtpd SASL LOGIN failed | SASL LOGIN authentication failed, no queue ID | 0.4% of records | authentication |
| postfix/smtpd NOQUEUE reject | RCPT rejected with User unknown before queueing | 0.4% of records |
Realism Features
- Selected profile: SASL LOGIN on the submission service, short queue IDs (enable_long_queue_ids=no), one recipient per SMTP delivery (smtp_destination_recipient_limit=1), header rewriting for authenticated clients, show_user_unknown_table_name=no and mail-log timestamps in UTC.
- About 54,700 records a day (±3% from day to day) on a UTC hour-of-day curve: 0.39-0.42 records per second at night rising to 1.02-1.07 between 11:00 and 14:00, when staff send 67% of the messages. The curve repeats every day with no weekly cycle, so weekends look like weekdays.
- The 150 staff users submit about 4,500 messages a day from their own workstation (ws-NNNN.corp.example) or a VPN laptop without reverse DNS (unknown). Each user has a steady share of about 10 to 60 messages a day and sends mail every day; a message goes to one to five external recipients (one 68%, two 16%, three 8%, four and five 4% each).
- About 3% of staff submissions start with a mistyped or outdated password: one failure is more common than two, two more common than three, retries follow a median 14 seconds later within the same smtpd process, and after three failures the user gives up. About 4% address an unknown local mailbox and are rejected before queueing; most users resend about a minute later. About 2% of all SASL attempts fail.
- Eight application service accounts send notifications, reports and job output around the clock, about 5,600 messages a day; they rarely fail authentication (once, then succeed a few seconds later) and rarely address an unknown mailbox.
- Message sizes are right-skewed, up to the 10 MB default message_size_limit for staff mail with attachments. Each recipient is delivered by its own smtp process to one of three relays. qmgr keeps one process ID; smtpd, cleanup and smtp processes serve several jobs, exit after 100 seconds idle or 100 jobs and are replaced with increasing process IDs, so process IDs repeat across unrelated clients.
- Records of one message are seconds apart instead of milliseconds, so printed delay and delays show a median total of about 5 seconds at busy hours and 9 at night, where a real relay usually delivers in under a second. Timestamps have one-second resolution, and queue IDs have a random inode part.
- A selected successful-delivery path, not a complete Postfix mail log: no connection, disconnect or TLS records, postscreen, local or LMTP delivery, bounces, deferred retries or conn_use=, and all deliveries go to external relays. The failure reason is the Cyrus SASL wording. No complete raw Postfix 3.8.3+ log of the chain was found, so it joins documented line formats. Each episode adds one run of three failures and one five-recipient message to the ordinary counts.
Sample Output
{
"@timestamp": "2026-09-01T11:07:59+00:00",
"ecs": {
"version": "8.17.0"
},
"event": {
"action": "queue-created",
"category": [
"email"
],
"dataset": "postfix.syslog",
"kind": "event",
"original": "Sep 1 11:07:59 mail-01.corp.example postfix/smtpd[59392]: 8E5BDF3BD5: client=ws-0324.corp.example[10.80.21.78], sasl_method=LOGIN, sasl_username=alex.hansen@corp.example",
"outcome": "success",
"type": [
"info"
]
},
"host": {
"ip": [
"10.80.0.5"
],
"name": "mail-01.corp.example"
},
"log": {
"level": "info",
"syslog": {
"appname": "postfix/smtpd"
}
},
"message": "8E5BDF3BD5: client=ws-0324.corp.example[10.80.21.78], sasl_method=LOGIN, sasl_username=alex.hansen@corp.example",
"observer": {
"hostname": "mail-01.corp.example",
"ip": "10.80.0.5",
"product": "Postfix",
"type": "mail",
"vendor": "Postfix"
},
"postfix": {
"queue_id": "8E5BDF3BD5",
"sasl": {
"username": "alex.hansen@corp.example"
},
"service": "smtpd"
},
"process": {
"name": "postfix/smtpd",
"pid": 59392
},
"related": {
"hosts": [
"mail-01.corp.example"
],
"ip": [
"10.80.21.78"
],
"user": [
"alex.hansen@corp.example"
]
},
"source": {
"ip": "10.80.21.78"
},
"tags": [
"postfix",
"preserve_original_event"
],
"user": {
"name": "alex.hansen@corp.example"
}
}Parameters
| Parameter | Default | Description |
|---|---|---|
| anomaly_mode | true | Add the recurring anomaly episodes to the background; false keeps only background activity |
| anomaly_interval_hours | 24 | Hours from one episode start to the next due time, 1 to 8,760 |
| mail_host | mail-01.corp.example | Postfix hostname in the syslog line and generated Message-IDs |
| mail_ip | 10.80.0.5 | Postfix host IP |
Related Generators
Microsoft Exchange Message Tracking
Exchange Server 2019 message tracking — SMTP receive/send, mailbox delivery, transport routing, shadow redundancy, anti-spam filtering, distribution group expansion, and delivery failure DSNs.
Kaspersky Secure Mail Gateway
Kaspersky Secure Mail Gateway (KSMG) ScanLogic events — anti-virus, anti-spam, anti-phishing, content filtering, mail authentication (SPF/DKIM/DMARC), KATA integration, message backup, and scan failure events in ECS-compatible JSON.
Fortinet FortiMail
FortiMail email security gateway — mail statistics, SMTP protocol events, antispam verdict (clean/spam/phishing), antivirus scanning with quarantine actions, and system administration logs.