All Apps and Add-ons

How does Splunk Streams handle a SMTP stream containing multiple emails?

davidwaugh
Path Finder

Hello
I am new to Splunk and interested in the capabilities of Splunk Stream.

If Splunk stream receives a SMTP session that contains multiple emails, does the stream get split into the individual emails?

For example a typical SMTP session between two mail servers will contain multiple emails in a single TCP session (such as when email is being relayed from one mail server to another).

Does anyone have an examples of this would be visible in Splunk?
Thank you.

0 Karma

schandrasekar
Loves-to-Learn

Can someone explain how splunk stream can be used to get email headers 

0 Karma
Get Updates on the Splunk Community!

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...