What is email journaling?
The LibraCyber Email Archiver can archive the incoming, outgoing and internal emails of all Google Workspace users in real-time. To accomplish this, the Google Workspace journal function must be configured. This is the only way to ensure that all emails are archived entirely.
Thanks to the journaling functionality, at the time of sending and receiving, a copy of the respective email is created by Google Workspace.
The copy is then attached to a so-called journal report and stored in a special journal mailbox. The journal report contains information about the actual senders and recipients; Google Workspace also resolves BCC recipients and distribution lists.
Setup Journaling SMTP (from v22.08)
LibraCyber Email Archiver v22.08 natively supports Google Workspace SMTP journaling , this solution will give a more easy configuration and straight forward journaling mailflow to the archiver.
The instructions below will guide you in configuring SMTP journaling from Google Workspace to the LibraCyber Email Archiver.
Email Archiver configuration
Follow these steps to configure the Email Archiver to receive email journaling from Google Workspace via SMTP journaling:
- Select the menu Archiver > Mail Sources > Journaling SMTP
- Press the + icon
- Authentication: SPF
- Type: Forwarding
- Hosted by: Google
- Sender domain: your domain
- Save
Google Workspace Configuration
In order to send a copy of email (internal, outbound, inbound) from Google Workspace to the Email Archiver you can proceed in two way:
- Archive all mail, with this guide: Google Workspace Configuration - Route to Archiver
- Archive all mail only for specific users, with this guide: Google Workspace Configuration - Route to archiver (filtered by users)
Google Workspace Configuration - Route to Archiver
This steps create a new route in Google Workspace to send a copy of all email (internal, outbound, inbound) to the Email Archiver.
- In your Google Admin console (at admin.google.com)...
- Go to Apps > Google Workspace > Settings for Gmail > Routing section
- Click on Add another rule
- Enter routing rule name ex:"Send to LibraCyber Archiver"
-
Messages to affect enable all checkbox: Inbound, Outbound, Internal - sending, Internal - receiving
- Also deliver to select Add more recipients and click ADD
-
Choose Basic option and add into Recipient address your journaling mailbox to send journal messages and save. The journaling mailbox has to be configured in this way archiver@<archiver-FQDN> as Recipient address.
- Click Add Setting.
- At the bottom, click Save
At this stage, Google Workspace is ready to send a copy of each email to your journaling mailbox.
On the Email Archiver you should see new emails coming.
Google Workspace Configuration - Route to Archiver (filtered by users)
This steps create a new route in Google Workspace to send a copy of all email (internal, outbound, inbound) only for selected tenant users to the Email Archiver.
With this configuration you'll need to create two routing configurations, sending and receiving.
Sending configuration
- In your Google Admin console (at admin.google.com)...
- Go to Apps > Google Workspace > Settings for Gmail > Routing section
- Click on Add another rule
- Enter routing rule name ex:"Send to LibraCyber Archiver - Sending rule"
-
Messages to affect enable all checkbox: Inbound, Outbound, Internal - sending, Internal - receiving
- Also deliver to select Add more recipients and click ADD
-
Choose Basic option and add into Recipient address your journaling mailbox to send journal messages and save. The journaling mailbox has to be configured in this way archiver@<archiver-FQDN> as Recipient address.
- Click Add Setting.
- Click Show options.
- Go to C. Envelope filter and select Only affect specific envelope senders
Case A: To enable archiving for a single user,
- Select the Single email address option from the list
- Provide the email address of the user
Case B: To enable archiving for a group,
- Select the Group Membership (only sent mail) option from the list
- Select the Group of users from the list
- At the bottom, click Save
Receiving configuration
- In your Google Admin console (at admin.google.com)...
- Go to Apps > Google Workspace > Settings for Gmail > Routing section
- Click on Add another rule
- Enter routing rule name ex:"Send to LibraCyber Archiver - Sending rule"
-
Messages to affect enable all checkbox: Inbound, Outbound, Internal - sending, Internal - receiving
- Also deliver to select Add more recipients and click ADD
-
Choose Basic option and add into Recipient address your journaling mailbox to send journal messages and save. The journaling mailbox has to be configured in this way archiver@<archiver-FQDN> as Recipient address.
- Click Add Setting.
- Click Show options.
- Go to C. Envelope filter and select Only affect specific envelope recipients
Case A: To enable archiving for a single user,
- Select the Single email address option from the list
- Provide the email address of the user
Case B: To enable archiving for a group,
- Select the Group Membership (only sent mail) option from the list
- Select the Group of users from the list
- At the bottom, click Save
Setup Journaling IMAP (deprecated by v22.08)
Google Workspace can be managed by journaling IMAP.
The instructions below will guide you in configuring journaling IMAP from Google Workspace to the LibraCyber Email Archiver.
To set up Journaling IMAP, you need a Journaling mailbox, it can be an external mailbox or on your Google Workspace account, if you choose to use external mailbox skip the first step.
Manage access to less secure apps (Admin)
You can allow users to turn on access for less secure apps or disable their ability to allow less secure apps.
- Sign in to your Google Admin console Sign in using an administrator account
- Go to the settings for Less secure apps: From the Admin console Home page, go to Security > Less secure apps To see Security on the Home page, you might have to click More controls at the bottom OR, if the "Less secure apps" option isn't visible: From the Admin console Home page, go to Security > Basic settings To see Security on the Home page, you might have to click More controls at the bottom Then, under Less secure apps, click Go to settings for less secure apps
- Select the setting for less secure apps: Allow users to manage their access to less secure apps Users can turn on or turn off access to less secure apps.
- Apply settings for organizational units or your domain. You can also customize permissions for groups of users. To apply the setting to everyone, leave the top organizational unit selected. Otherwise, select a child organizational unit. To apply settings to a group of users, check which group settings are on the left of your Admin console.
- Click Save
- Sign in to your Google journaling mailbox as a user.
- Enable "Less secure app access" you can turn it on.
Email Archiver configuration: configure the Journaling IMAP mailbox
Follow these steps to configure the Email Archiver to receive email journaling from Google Workspace:
- Select the menu Archiver > Mail Sources > Journaling IMAP
- Press the + icon
- Connections > IMAP
- Set Active
- Hostname > enter your IMAP Google Workspace email domain
- Port > IMAP port
- Username > enter Journaling IMAP dedicated mailbox username
- Password > enter Journaling IMAP dedicated mailbox password
- Encryption > enter encryption protocol
- Type > select Forwarding
-
Enable > Delete mails after indexing
- Validate
- Check only INBOX send Sent messages folders
- Save
The Email Archiver is now ready to receive email journals from Google Workspace.
Google Workspace Configuration
In order to send a copy of email (internal, outbound, inbound) from Google Workspace to the Email Archiver you can proceed in two way:
- Archive all mail, with this guide: Google Workspace Configuration - Route to Archiver
- Archive all mail only for specific users, with this guide: Google Workspace Configuration - Route to archiver (filtered by users)
Google Workspace Configuration - Route to Archiver
This steps create a new route in Google Workspace to send a copy of all email (internal, outbound, inbound) to the Email Archiver.
- In your Google Admin console (at admin.google.com)...
- Go to Apps > Google Workspace > Settings for Gmail > Routing section
- Click on Add another rule
- Enter routing rule name ex:"Send to LibraCyber Archiver"
-
Messages to affect enable all checkbox: Inbound, Outbound, Internal - sending, Internal - receiving
- Also deliver to select Add more recipients and click ADD
-
Choose Basic option and add into Recipient address your journaling mailbox to send journal messages and save. The journaling mailbox is the mailbox configured in the previous steps.
- Click Add Setting.
- At the bottom, click Save
At this stage, Google Workspace is ready to send a copy of each email to your journaling mailbox.
On the Email Archiver you should see new emails coming.
Google Workspace Configuration - Route to Archiver (filtered by users)
This steps create a new route in Google Workspace to send a copy of all email (internal, outbound, inbound) only for selected tenant users to the Email Archiver.
With this configuration you'll need to create two routing configurations, sending and receiving.
Sending configuration
- In your Google Admin console (at admin.google.com)...
- Go to Apps > Google Workspace > Settings for Gmail > Routing section
- Click on Add another rule
- Enter routing rule name ex:"Send to LibraCyber Archiver - Sending rule"
-
Messages to affect enable all checkbox: Inbound, Outbound, Internal - sending, Internal - receiving
- Also deliver to select Add more recipients and click ADD
-
Choose Basic option and add into Recipient address your journaling mailbox to send journal messages and save. The journaling mailbox is the mailbox configured in the previous steps.
- Click Add Setting.
- Click Show options.
- Go to C. Envelope filter and select Only affect specific envelope senders
Case A: To enable archiving for a single user,
- Select the Single email address option from the list
- Provide the email address of the user
Case B: To enable archiving for a group,
- Select the Group Membership (only sent mail) option from the list
- Select the Group of users from the list
- At the bottom, click Save
Receiving configuration
- In your Google Admin console (at admin.google.com)...
- Go to Apps > Google Workspace > Settings for Gmail > Routing section
- Click on Add another rule
- Enter routing rule name ex:"Send to LibraCyber Archiver - Sending rule"
-
Messages to affect enable all checkbox: Inbound, Outbound, Internal - sending, Internal - receiving
- Also deliver to select Add more recipients and click ADD
-
Choose Basic option and add into Recipient address your journaling mailbox to send journal messages and save. The journaling mailbox is the mailbox configured in the previous steps.
- Click Add Setting.
- Click Show options.
- Go to C. Envelope filter and select Only affect specific envelope recipients
Case A: To enable archiving for a single user,
- Select the Single email address option from the list
- Provide the email address of the user
Case B: To enable archiving for a group,
- Select the Group Membership (only sent mail) option from the list
- Select the Group of users from the list
- At the bottom, click Save