All Apps and Add-ons

IMAP Mailbox - Duplicate events

d4rk_sp1d3r
Loves-to-Learn Lots

Hi.

I installed IMAP Mailbox app in our distributed server deployment where setting is Heavy forwarder ---> Clustered indexer ---> Search Head and followed the steps as indicated on splunkbase. I installed it to 1 heavy forwarder --> 3 indexers ---> 1 search head. It seems to work but i noticed that it duplicates the logs every certain minutes probably 5 minutes. I was sure that i configured disabled = true on all inputs.conf other than the one in the HF. There are no imap.conf configuration on the other servers IMAPmailbox/local folder. I installed the app on all the indexer manually but i was informed that we have to create the index on a certain app that is deployed to the indexers. I had to remove all the app from the 3 indexers to comply. When I try to enable the imap.conf script again, it downloaded the email but again creating duplicates. In imap.conf i configured the following as DeleteWhenDone =False and IMAPsearch = UNDELETED. This is also the setting in my single splunk deployment and it was working fine. Do you know what causes the duplicates? Are these types of issues supported by splunk support?

Regards,
Ronald

0 Karma

d4rk_sp1d3r
Loves-to-Learn Lots

tried to remove the app from the search head and it still gets duplicates every 5 mins. only the heavy forwarder has it installed and the 3 clustered indexers has the imap index with no app. still no solution. may try other app. do you know a better one?

0 Karma

mcrozier
Splunk Employee
Splunk Employee

You could try  TA-mailclient

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud's AI Assistant in Action Series: Auditing Compliance and ...

This is the third post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

What You Read The Most: Splunk Lantern’s Most Popular Articles!

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...