Monitor unlimited number of servers
Filter log events
Create email and web-based reports

Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content

Event ID: 17220 Source: SmtpEvt

An unknown SMTP command
0000: 58 45 58 43 48 35 30 20   XEXCH50
0008: 31 30 32 30               1020
As per ME312357, if the SMTP content application filter is installed, you must explicitly state which SMTP commands are permitted. Event 1722 occurs if you do not explicitly state the SMTP commands that are in use.
See ME322234. This message is logged when the SMTP Filter service in ISA Server receives a command that is longer than the permitted length that is listed under the SMTP Commands tab in the SMTP Filter properties. The command that was passed appears in the DATA section of the event message. If the command was expected, you must modify the permitted length of this command in the SMTP Filter properties SMTP Commands tab.

Windows Event Log Analysis Splunk App

Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to



Cisco ASA Log Analyzer Splunk App

Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.