Shadyr

Registered
Oct 16, 2008
3
0
51
Is there a way to get logs for webmail to display the actual source IP of the login? Or maybe another logfile contains this info? When I look at logs (/var/log/maillog) for webmail users, I just get this, which isn't very useful:

maillog.1:Apr 18 20:15:30 web3 dovecot: imap-login: Login: user=<[email protected]>, method=PLAIN, rip=127.0.0.1, lip=127.0.0.1, secured

Since I'm pretty sure they aren't sitting on the console, I'd like to see where they are really coming from. In this case, an email account got phished and the owner wanted to know where the logins to it had originated.

Thanks!
 

cPanelTristan

Quality Assurance Analyst
Staff member
Oct 2, 2010
7,607
40
248
somewhere over the rainbow
cPanel Access Level
Root Administrator
You should be able to see the access in /usr/local/cpanel/logs/access_log as well during that timestamp. I see entries when I tried to log into webmail on port 2096 for my IP as well as the email account I was trying to use. A grep like this should work:

Code:
grep [email protected] /usr/local/cpanel/logs/access_log