We have previously used the Splunk TA-mail client Add-on (with a minor modification to input email from MS Exchange):
https://splunkbase.splunk.com/app/3200
Latest version was released Nov 2017, and supports up to Splunk 7.0 (but has incompatibilities with Splunk 7.1.x ++)
After we upgraded to Splunk 7.1, the Add-on stopped working, no longer indexed email . . . and noticed that:
The view for App configuration is blank / broken
Differences in password.conf implementations
Modular input and python configuration / code
How to make this app working for the higher versions of the TA mail client app?
Can you re-make the input stanza and try indexing afterwards?
You might also want to try using either 1.3.5 (December 2017), 1.3.7-dev, or a current snapshot of master (https://github.com/seunomosowon/TA-mailclient)
I can report that I started using 1.3.7-dev in Splunk 7.1.4 and it indexed mail successfully.
I have tried using 1.3.5 (December 2017), 1.3.7-dev, or a current snapshot of master (https://github.com/seunomosowon/TA-mailclient) But i haven't seen The view for App configuration in the Data input section. I am using Version: 7.1.2.
Can you please help me if there is any working version of the app with this version o f splunk?