<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can someone explain how splunk stream can be used to get email headers in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Can-someone-explain-how-splunk-stream-can-be-used-to-get-email/m-p/512492#M62800</link>
    <description>&lt;P&gt;In the message tracking logs, you should see field called event which actually contains SEND,DELIVER,RECEIVE&amp;nbsp;&lt;/P&gt;&lt;P&gt;if you can minus the time of send from time of receive &amp;nbsp;by message_id then you should get what you want.&lt;/P&gt;</description>
    <pubDate>Wed, 05 Aug 2020 04:02:14 GMT</pubDate>
    <dc:creator>thambisetty</dc:creator>
    <dc:date>2020-08-05T04:02:14Z</dc:date>
    <item>
      <title>Can someone explain how splunk stream can be used to get email headers</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Can-someone-explain-how-splunk-stream-can-be-used-to-get-email/m-p/512489#M62799</link>
      <description>&lt;P&gt;The goal is to find the delay between the time sender sents the mail and recipient receive the mail , if the delay is more than 10 mins then alert&lt;/P&gt;
&lt;P&gt;Options tried:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;Message tracking logs C:\Program Files\Microsoft\Exchange Server\V14\TransportRoles\Logs\MessageTracking in exchange server2010. But the logs didn provide the actual time when the user sent the email, also the original IP of the sender is replaced with LB/Exchange server/relay server/firewall. &lt;/LI-CODE&gt;
&lt;P&gt;So now I looking for other options. One of them is using Splunk stream.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please provide your suggestions.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Aug 2020 04:30:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Can-someone-explain-how-splunk-stream-can-be-used-to-get-email/m-p/512489#M62799</guid>
      <dc:creator>schandrasekar</dc:creator>
      <dc:date>2020-08-05T04:30:56Z</dc:date>
    </item>
    <item>
      <title>Re: Can someone explain how splunk stream can be used to get email headers</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Can-someone-explain-how-splunk-stream-can-be-used-to-get-email/m-p/512492#M62800</link>
      <description>&lt;P&gt;In the message tracking logs, you should see field called event which actually contains SEND,DELIVER,RECEIVE&amp;nbsp;&lt;/P&gt;&lt;P&gt;if you can minus the time of send from time of receive &amp;nbsp;by message_id then you should get what you want.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Aug 2020 04:02:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Can-someone-explain-how-splunk-stream-can-be-used-to-get-email/m-p/512492#M62800</guid>
      <dc:creator>thambisetty</dc:creator>
      <dc:date>2020-08-05T04:02:14Z</dc:date>
    </item>
    <item>
      <title>Re: Can someone explain how splunk stream can be used to get email headers</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Can-someone-explain-how-splunk-stream-can-be-used-to-get-email/m-p/512501#M62803</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/129407"&gt;@thambisetty&lt;/a&gt;&amp;nbsp;date_time doesn't look like the time when the message was sent by the user. Also, I am looking for original IP field to be the actual sender IP&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.microsoft.com/en-us/exchange/mail-flow/transport-logs/message-tracking?view=exchserver-2019" target="_blank"&gt;https://docs.microsoft.com/en-us/exchange/mail-flow/transport-logs/message-tracking?view=exchserver-2019&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Aug 2020 05:48:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Can-someone-explain-how-splunk-stream-can-be-used-to-get-email/m-p/512501#M62803</guid>
      <dc:creator>schandrasekar</dc:creator>
      <dc:date>2020-08-05T05:48:29Z</dc:date>
    </item>
  </channel>
</rss>

