All Apps and Add-ons

IMAP Mailbox - Duplicate events

d4rk_sp1d3r
Loves-to-Learn Lots

Hi.

I installed IMAP Mailbox app in our distributed server deployment where setting is Heavy forwarder ---> Clustered indexer ---> Search Head and followed the steps as indicated on splunkbase. I installed it to 1 heavy forwarder --> 3 indexers ---> 1 search head. It seems to work but i noticed that it duplicates the logs every certain minutes probably 5 minutes. I was sure that i configured disabled = true on all inputs.conf other than the one in the HF. There are no imap.conf configuration on the other servers IMAPmailbox/local folder. I installed the app on all the indexer manually but i was informed that we have to create the index on a certain app that is deployed to the indexers. I had to remove all the app from the 3 indexers to comply. When I try to enable the imap.conf script again, it downloaded the email but again creating duplicates. In imap.conf i configured the following as DeleteWhenDone =False and IMAPsearch = UNDELETED. This is also the setting in my single splunk deployment and it was working fine. Do you know what causes the duplicates? Are these types of issues supported by splunk support?

Regards,
Ronald

0 Karma

d4rk_sp1d3r
Loves-to-Learn Lots

tried to remove the app from the search head and it still gets duplicates every 5 mins. only the heavy forwarder has it installed and the 3 clustered indexers has the imap index with no app. still no solution. may try other app. do you know a better one?

0 Karma

mcrozier
Splunk Employee
Splunk Employee

You could try  TA-mailclient

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Dashboard Studio Challenge - Learn New Tricks, Showcase Your Skills, and Win Prizes!

Reimagine what you can do with your dashboards. Dashboard Studio is Splunk’s newest dashboard builder to ...

Introducing Edge Processor: Next Gen Data Transformation

We get it - not only can it take a lot of time, money and resources to get data into Splunk, but it also takes ...

Take the 2021 Splunk Career Survey for $50 in Amazon Cash

Help us learn about how Splunk has impacted your career by taking the 2021 Splunk Career Survey. Last year’s ...