<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can Splunk be used to sort through emails? in Reporting</title>
    <link>https://community.splunk.com/t5/Reporting/Can-Splunk-be-used-to-sort-through-emails/m-p/47934#M978</link>
    <description>&lt;P&gt;If what you are after is a general idea of whether you can index and search larger blocks of text like e-mails, then yes. I have a few hundred thousand emails indexed. But I do it a little differently. I store the data in a database and use a scripted input to format the content in a way that makes it easy to create fields in transforms.conf&lt;/P&gt;

&lt;P&gt;edit: I would add, like the commenter above, it's probably not the best tool for this kind of job though.&lt;/P&gt;</description>
    <pubDate>Sat, 17 Aug 2013 22:16:35 GMT</pubDate>
    <dc:creator>jpass</dc:creator>
    <dc:date>2013-08-17T22:16:35Z</dc:date>
    <item>
      <title>Can Splunk be used to sort through emails?</title>
      <link>https://community.splunk.com/t5/Reporting/Can-Splunk-be-used-to-sort-through-emails/m-p/47931#M975</link>
      <description>&lt;P&gt;Can emails be sent directly to a Splunk server so it can go through and alert on emails of interest? &lt;/P&gt;</description>
      <pubDate>Tue, 28 May 2013 20:13:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Can-Splunk-be-used-to-sort-through-emails/m-p/47931#M975</guid>
      <dc:creator>marykyeung</dc:creator>
      <dc:date>2013-05-28T20:13:07Z</dc:date>
    </item>
    <item>
      <title>Re: Can Splunk be used to sort through emails?</title>
      <link>https://community.splunk.com/t5/Reporting/Can-Splunk-be-used-to-sort-through-emails/m-p/47932#M976</link>
      <description>&lt;P&gt;You can't send it directly to splunk but I guess you could send it to an account on a server and index the mbox file on the server.&lt;/P&gt;

&lt;P&gt;However, I am not sure this is the best technology fit.   Usually people use Splunk to monitor everything at the mail server rather than sending messages directly to it to index.&lt;/P&gt;</description>
      <pubDate>Wed, 29 May 2013 02:06:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Can-Splunk-be-used-to-sort-through-emails/m-p/47932#M976</guid>
      <dc:creator>okrabbe_splunk</dc:creator>
      <dc:date>2013-05-29T02:06:06Z</dc:date>
    </item>
    <item>
      <title>Re: Can Splunk be used to sort through emails?</title>
      <link>https://community.splunk.com/t5/Reporting/Can-Splunk-be-used-to-sort-through-emails/m-p/47933#M977</link>
      <description>&lt;P&gt;There are people who have indexed maildir directory trees or individual files using Splunk. Because there are datestamps in the file, it's not too bad at figuring out the timestamp. However, you might have to futz with the header fields to make subject et al. searchable.&lt;/P&gt;

&lt;P&gt;Search Splunk-Base for "maildir" to find more examples.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jun 2013 20:29:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Can-Splunk-be-used-to-sort-through-emails/m-p/47933#M977</guid>
      <dc:creator>jtrucks</dc:creator>
      <dc:date>2013-06-13T20:29:44Z</dc:date>
    </item>
    <item>
      <title>Re: Can Splunk be used to sort through emails?</title>
      <link>https://community.splunk.com/t5/Reporting/Can-Splunk-be-used-to-sort-through-emails/m-p/47934#M978</link>
      <description>&lt;P&gt;If what you are after is a general idea of whether you can index and search larger blocks of text like e-mails, then yes. I have a few hundred thousand emails indexed. But I do it a little differently. I store the data in a database and use a scripted input to format the content in a way that makes it easy to create fields in transforms.conf&lt;/P&gt;

&lt;P&gt;edit: I would add, like the commenter above, it's probably not the best tool for this kind of job though.&lt;/P&gt;</description>
      <pubDate>Sat, 17 Aug 2013 22:16:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Can-Splunk-be-used-to-sort-through-emails/m-p/47934#M978</guid>
      <dc:creator>jpass</dc:creator>
      <dc:date>2013-08-17T22:16:35Z</dc:date>
    </item>
  </channel>
</rss>

