Sendmail logs auth failures, forged relay hostnames, TLS rejections, and Milter actions on every mail transaction. It's one of the most overlooked sources of threat telemetry out there. The Sendmail Content Pack for Graylog parses it. graylog.org/post/sendmai...
Sendmail Data In Graylog
Graylog Sendmail Content Pack parses, enriches, and maps mail server logs to GIM, turning routine MTA data into real threat detection signal."
graylog.org