All Apps and Add-ons

How to make TA-mailclient work with Splunk 7.1.X?

chayboa
Engager

We have previously used the Splunk TA-mail client Add-on (with a minor modification to input email from MS Exchange):
https://splunkbase.splunk.com/app/3200
Latest version was released Nov 2017, and supports up to Splunk 7.0 (but has incompatibilities with Splunk 7.1.x ++)
After we upgraded to Splunk 7.1, the Add-on stopped working, no longer indexed email . . . and noticed that:
The view for App configuration is blank / broken
Differences in password.conf implementations
Modular input and python configuration / code
How to make this app working for the higher versions of the TA mail client app?

ssmiesko
Explorer

Can you re-make the input stanza and try indexing afterwards?

You might also want to try using either 1.3.5 (December 2017), 1.3.7-dev, or a current snapshot of master (https://github.com/seunomosowon/TA-mailclient)

I can report that I started using 1.3.7-dev in Splunk 7.1.4 and it indexed mail successfully.

0 Karma

chayboa
Engager

I have tried using 1.3.5 (December 2017), 1.3.7-dev, or a current snapshot of master (https://github.com/seunomosowon/TA-mailclient) But i haven't seen The view for App configuration in the Data input section. I am using Version: 7.1.2.

Can you please help me if there is any working version of the app with this version o f splunk?

0 Karma
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...