This patterndb does not work. Remove this line to try it. However, it will still not work. This tries to examine the Postfix mail handling postfix.org postfix @ESTRING:queueid: @client=@ESTRING:pfremotehost:[@@IPvANY:pfremoteip@] 37AA230003B: client=example.com[2109:9876:34ab::f1] @ESTRING:queueid: @message-id=@QSTRING:msgid:<>@ 7857B3001E2: message-id=<201102101555.3RHHEQ8024@desktop> @ESTRING:queueid: @to=@QSTRING:toaddress:<>@, orig_to=@QSTRING:origto:<>@, relay=@ESTRING:relay:,@ delay=@ANYSTRING:deliverystatus@ 471C2300527: to=<example@mail.example.com>, orig_to=<example@example.com>, relay=example.com[2109:9876:34ab::f1]:25, delay=0.24, delays=0.04/0.01/0.11/0.08, dsn=2.0.0, status=sent (250 2.0.0 Ok: queued as 6FC19612F6) @ESTRING:queueid: @removed M06 ${queueid}@1/${queueid}@4 mail to=<${toaddress}@2> from=<${pffrom}@3> connection from=${pfremotehost}@5[${pfremoteip}@5] msgid=<${msgid}@4> orig_to=<${origto}@2> $(grep ($HOST == $HOST) $queueid) delay=${deliverystatus}@2 @ESTRING:queueid: @from=@QSTRING:pffrom:<>@, size=@NUMBER@, nrcpt=@ANYSTRING@