All Apps and Add-ons

IMAP Mailbox - Duplicate events

d4rk_sp1d3r
Loves-to-Learn Lots

Hi.

I installed IMAP Mailbox app in our distributed server deployment where setting is Heavy forwarder ---> Clustered indexer ---> Search Head and followed the steps as indicated on splunkbase. I installed it to 1 heavy forwarder --> 3 indexers ---> 1 search head. It seems to work but i noticed that it duplicates the logs every certain minutes probably 5 minutes. I was sure that i configured disabled = true on all inputs.conf other than the one in the HF. There are no imap.conf configuration on the other servers IMAPmailbox/local folder. I installed the app on all the indexer manually but i was informed that we have to create the index on a certain app that is deployed to the indexers. I had to remove all the app from the 3 indexers to comply. When I try to enable the imap.conf script again, it downloaded the email but again creating duplicates. In imap.conf i configured the following as DeleteWhenDone =False and IMAPsearch = UNDELETED. This is also the setting in my single splunk deployment and it was working fine. Do you know what causes the duplicates? Are these types of issues supported by splunk support?

Regards,
Ronald

0 Karma

d4rk_sp1d3r
Loves-to-Learn Lots

tried to remove the app from the search head and it still gets duplicates every 5 mins. only the heavy forwarder has it installed and the 3 clustered indexers has the imap index with no app. still no solution. may try other app. do you know a better one?

0 Karma

mcrozier
Splunk Employee
Splunk Employee

You could try  TA-mailclient

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...