What is the proper method to do this in SM?
The way I would have done this in our prior email server (CGP) would be to locate some record related to the message you want to examine... (typically by from or to address and time of day)... from that record grab the Message ID... then run that Message ID in the search operation... poof, all records associated with that message appear.
If I try that method using the SM SMTP logs, I get tons of totally unrelated SMTP records all seemingly stamped with the Message ID I'm searching for, I can't explain it unless the field I think is the message ID isn't.
If someone from SM can respond, I can send a thorough example demonstrating what I'm talking about.
For the public, here is an SMTP log ecord, the hilited field I am using as the Message ID in my 2nd search hoping to get all the related SMTP messages for just that message: