<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk for IMAP stop indexing data in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-IMAP-stop-indexing-data/m-p/72973#M4613</link>
    <description>&lt;P&gt;Bump. I have a similar issue and the same questions. &lt;/P&gt;

&lt;P&gt;If I run via the commandline (as James did above) and pump the output to a log file the log file will get the IMAP entries for the mail in the folder, but the mail index in splunk never gets any data &lt;/P&gt;</description>
    <pubDate>Wed, 23 Jan 2013 04:57:29 GMT</pubDate>
    <dc:creator>kristan</dc:creator>
    <dc:date>2013-01-23T04:57:29Z</dc:date>
    <item>
      <title>Splunk for IMAP stop indexing data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-IMAP-stop-indexing-data/m-p/72972#M4612</link>
      <description>&lt;P&gt;We installed and configured splunk for imap.&lt;BR /&gt;
it worked and indexed data but from some reason it stopped indexing data after a few hours.&lt;/P&gt;

&lt;P&gt;Troubleshooting:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;verified that the mailbox contains new messages&lt;/LI&gt;
&lt;LI&gt;verified that the mailbox was not full.&lt;/LI&gt;
&lt;LI&gt;when I ran "/opt/splunk/bin/splunk cmd python /splunk/etc/apps/imap/bin/getimap.py --debug" it connected to the mailbox but from some reason did not find any new messages.&lt;/LI&gt;
&lt;LI&gt;I've deleted some of the old messages and change imap.conf filtering to: imapSearch = UNDELETED instead of "imapSearch = UNDELETED SMALLER 204800"&lt;/LI&gt;
&lt;LI&gt;After the changes splunk index the new messages&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;I've enabled debug in imap.conf but not sure what value it adds..&lt;/P&gt;

&lt;P&gt;I want to know why it stopped and verify it won't happen again.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Where are the imap app log files located?&lt;BR /&gt;
How can I troubleshoot it further?&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Dec 2012 12:19:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-IMAP-stop-indexing-data/m-p/72972#M4612</guid>
      <dc:creator>jamesm84</dc:creator>
      <dc:date>2012-12-25T12:19:45Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk for IMAP stop indexing data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-IMAP-stop-indexing-data/m-p/72973#M4613</link>
      <description>&lt;P&gt;Bump. I have a similar issue and the same questions. &lt;/P&gt;

&lt;P&gt;If I run via the commandline (as James did above) and pump the output to a log file the log file will get the IMAP entries for the mail in the folder, but the mail index in splunk never gets any data &lt;/P&gt;</description>
      <pubDate>Wed, 23 Jan 2013 04:57:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-IMAP-stop-indexing-data/m-p/72973#M4613</guid>
      <dc:creator>kristan</dc:creator>
      <dc:date>2013-01-23T04:57:29Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk for IMAP stop indexing data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-IMAP-stop-indexing-data/m-p/72974#M4614</link>
      <description>&lt;P&gt;You can always search the splunk internal index for errors for the script.&lt;/P&gt;

&lt;P&gt;index=_internal imap source="*splunkd.log"&lt;/P&gt;

&lt;P&gt;See what you may find.&lt;/P&gt;

&lt;P&gt;Also you can " tail -f var/log/splunk/python.log" file too.&lt;/P&gt;

&lt;P&gt;I also noticed that if you don't delete your email after indexing "deleteWhenDone = True" in imap.conf, then the python script can take a looooong time to find the next set of emails to index. I noticed the script back logged for 2 hours on my install. I had to purge my mail box and then enable the delete option and things were ok again.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Apr 2014 05:41:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-IMAP-stop-indexing-data/m-p/72974#M4614</guid>
      <dc:creator>pbalsley</dc:creator>
      <dc:date>2014-04-04T05:41:56Z</dc:date>
    </item>
  </channel>
</rss>

