<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Incoming email info from Cisco ESA in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Incoming-email-info-from-Cisco-ESA/m-p/262785#M50438</link>
    <description>&lt;P&gt;Did you have issues receiving these logs before? Or is this the first time? Did you make any changes to configuration files or upgrade anything in Splunk? &lt;/P&gt;

&lt;P&gt;Since I do not know your environment, I cannot verify with what you’ve given me whether this is an issue with Splunk, Cisco, or an intermediary network/security product in between. Going through this systematically will allow you to determine where the issue is. Try going through some troubleshooting steps. Start tracing it from the source to the destination. &lt;/P&gt;

&lt;P&gt;Try sending an email from your personal email to your work email and use that to trace the event from start to finish.&lt;/P&gt;

&lt;P&gt;Verify whether the event appears in the logs from the appliance. &lt;/P&gt;

&lt;P&gt;If yes,&lt;/P&gt;

&lt;P&gt;Verify if the appliance is forwarding those logs to the syslog server.&lt;/P&gt;

&lt;P&gt;If yes,&lt;/P&gt;

&lt;P&gt;Find the event in the syslog server and verify if the event was sorted (based on your syslog configuration file rules) into the appropriate directory.&lt;/P&gt;

&lt;P&gt;If yes,&lt;/P&gt;

&lt;P&gt;Verify the Splunk forwarder on the syslog server is configured to monitor that directory.&lt;/P&gt;

&lt;P&gt;If yes,&lt;/P&gt;

&lt;P&gt;Determine if the forwarder sent that event to the indexer. At this point you should be able to simply search for the event. Search all indexes, &lt;CODE&gt;index=* youremail@yourdomain.com&lt;/CODE&gt;, for example. &lt;/P&gt;

&lt;P&gt;Hope that helps.&lt;/P&gt;</description>
    <pubDate>Tue, 31 Jan 2017 13:17:34 GMT</pubDate>
    <dc:creator>adayton20</dc:creator>
    <dc:date>2017-01-31T13:17:34Z</dc:date>
    <item>
      <title>Incoming email info from Cisco ESA</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Incoming-email-info-from-Cisco-ESA/m-p/262781#M50434</link>
      <description>&lt;P&gt;I installed the Cisco Security suite as well as the Cisco ESA add-on.&lt;/P&gt;

&lt;P&gt;I am forwarding the mail_logs from Cisco ESA to Splunk using syslog push over TCP.&lt;/P&gt;

&lt;P&gt;I can see info in the dashboards for outgoing messages but nothing from incoming.&lt;/P&gt;

&lt;P&gt;What do I need to configure to get the incoming messages info to show up?&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2017 15:10:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Incoming-email-info-from-Cisco-ESA/m-p/262781#M50434</guid>
      <dc:creator>heathramos</dc:creator>
      <dc:date>2017-01-27T15:10:20Z</dc:date>
    </item>
    <item>
      <title>Re: Incoming email info from Cisco ESA</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Incoming-email-info-from-Cisco-ESA/m-p/262782#M50435</link>
      <description>&lt;P&gt;1.) Have you verified whether or not inbound email is a configured log subscription in the ESA?&lt;/P&gt;

&lt;P&gt;2.) Have you verified whether or not the indexers are ingesting inbound email logs from the ESA?&lt;/P&gt;

&lt;P&gt;3.) Have you verified the logs are not going to a different sourcetype or generic sourcetype?&lt;/P&gt;</description>
      <pubDate>Sun, 29 Jan 2017 02:29:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Incoming-email-info-from-Cisco-ESA/m-p/262782#M50435</guid>
      <dc:creator>adayton20</dc:creator>
      <dc:date>2017-01-29T02:29:56Z</dc:date>
    </item>
    <item>
      <title>Re: Incoming email info from Cisco ESA</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Incoming-email-info-from-Cisco-ESA/m-p/262783#M50436</link>
      <description>&lt;P&gt;I don't see a log subscription specifically for inbound&lt;/P&gt;

&lt;P&gt;I am forwarding mail_logs&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jan 2017 20:29:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Incoming-email-info-from-Cisco-ESA/m-p/262783#M50436</guid>
      <dc:creator>heathramos</dc:creator>
      <dc:date>2017-01-30T20:29:09Z</dc:date>
    </item>
    <item>
      <title>Re: Incoming email info from Cisco ESA</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Incoming-email-info-from-Cisco-ESA/m-p/262784#M50437</link>
      <description>&lt;P&gt;for some reason eventtype=cisco-esa  policy_direction=outbound has records but eventtype=cisco-esa  policy_direction=inbound does not.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 12:40:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Incoming-email-info-from-Cisco-ESA/m-p/262784#M50437</guid>
      <dc:creator>heathramos</dc:creator>
      <dc:date>2020-09-29T12:40:19Z</dc:date>
    </item>
    <item>
      <title>Re: Incoming email info from Cisco ESA</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Incoming-email-info-from-Cisco-ESA/m-p/262785#M50438</link>
      <description>&lt;P&gt;Did you have issues receiving these logs before? Or is this the first time? Did you make any changes to configuration files or upgrade anything in Splunk? &lt;/P&gt;

&lt;P&gt;Since I do not know your environment, I cannot verify with what you’ve given me whether this is an issue with Splunk, Cisco, or an intermediary network/security product in between. Going through this systematically will allow you to determine where the issue is. Try going through some troubleshooting steps. Start tracing it from the source to the destination. &lt;/P&gt;

&lt;P&gt;Try sending an email from your personal email to your work email and use that to trace the event from start to finish.&lt;/P&gt;

&lt;P&gt;Verify whether the event appears in the logs from the appliance. &lt;/P&gt;

&lt;P&gt;If yes,&lt;/P&gt;

&lt;P&gt;Verify if the appliance is forwarding those logs to the syslog server.&lt;/P&gt;

&lt;P&gt;If yes,&lt;/P&gt;

&lt;P&gt;Find the event in the syslog server and verify if the event was sorted (based on your syslog configuration file rules) into the appropriate directory.&lt;/P&gt;

&lt;P&gt;If yes,&lt;/P&gt;

&lt;P&gt;Verify the Splunk forwarder on the syslog server is configured to monitor that directory.&lt;/P&gt;

&lt;P&gt;If yes,&lt;/P&gt;

&lt;P&gt;Determine if the forwarder sent that event to the indexer. At this point you should be able to simply search for the event. Search all indexes, &lt;CODE&gt;index=* youremail@yourdomain.com&lt;/CODE&gt;, for example. &lt;/P&gt;

&lt;P&gt;Hope that helps.&lt;/P&gt;</description>
      <pubDate>Tue, 31 Jan 2017 13:17:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Incoming-email-info-from-Cisco-ESA/m-p/262785#M50438</guid>
      <dc:creator>adayton20</dc:creator>
      <dc:date>2017-01-31T13:17:34Z</dc:date>
    </item>
    <item>
      <title>Re: Incoming email info from Cisco ESA</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Incoming-email-info-from-Cisco-ESA/m-p/262786#M50439</link>
      <description>&lt;P&gt;I believe it is an issue with ironport but not sure how to fix it.&lt;/P&gt;

&lt;P&gt;log files are coming over from ironport to splunk but the policy_direction field isn't associated with any incoming email logs&lt;/P&gt;

&lt;P&gt;this is a brand new set up&lt;/P&gt;</description>
      <pubDate>Tue, 31 Jan 2017 23:06:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Incoming-email-info-from-Cisco-ESA/m-p/262786#M50439</guid>
      <dc:creator>heathramos</dc:creator>
      <dc:date>2017-01-31T23:06:04Z</dc:date>
    </item>
    <item>
      <title>Re: Incoming email info from Cisco ESA</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Incoming-email-info-from-Cisco-ESA/m-p/262787#M50440</link>
      <description>&lt;P&gt;I forgot to update this thread with what was wrong with my set up&lt;/P&gt;

&lt;P&gt;it looks like my incoming mail policy had a space in it's name and Splunk had issues extracting fields from the logs because of it&lt;/P&gt;

&lt;P&gt;change the space to an underscore fixed the issue&lt;/P&gt;</description>
      <pubDate>Tue, 07 Feb 2017 15:02:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Incoming-email-info-from-Cisco-ESA/m-p/262787#M50440</guid>
      <dc:creator>heathramos</dc:creator>
      <dc:date>2017-02-07T15:02:36Z</dc:date>
    </item>
  </channel>
</rss>

