I am new to Splunk and interested in the capabilities of Splunk Stream.
If Splunk stream receives a SMTP session that contains multiple emails, does the stream get split into the individual emails?
For example a typical SMTP session between two mail servers will contain multiple emails in a single TCP session (such as when email is being relayed from one mail server to another).
Does anyone have an examples of this would be visible in Splunk?
Can someone explain how splunk stream can be used to get email headers