When Symantec Messaging Gateway (SMG) is configured to accept SMTP connections to the Authentication MTA on TCP port 587 and a connection fails to authenticate, an error is logged to the maillog but these events do not appear queries from the Status -> Message Audit Logs page.
While the failed SMTP AUTH event is logged in the message audit logs (MAL), you cannot search for AUTH events from the control center Status -> Message Audit Logs page.
This is a known issue and has been addressed in SMG 10.5.2. Please update when able.
The AUTH failure audit events may be searched from the SMG command line using the malquery command as follows:
<event time="1362174860" name="AUTH">}ö¬uùc|fail</event>
<event time="1362174837" name="ACCEPT">10.160.248.70:47127</event>