All Apps and Add-ons

Splunk app for exchange messages

pmovrich
Explorer

How does the exchange app determine, inbound vs outbound messages along with internal messages? These three pages within in the exchange app are not populating. I do see other e-mail messaging stats like message activity by username, etc.

Thanks

0 Karma
1 Solution

ahall_splunk
Splunk Employee
Splunk Employee

The determination depends on the message tracking logs. If the message comes in via SMTP, its an inbound message. If it goes out via SMTP, it's an outbound message. If its not inbound or outbound, it's internal.

View solution in original post

0 Karma

ahall_splunk
Splunk Employee
Splunk Employee

The determination depends on the message tracking logs. If the message comes in via SMTP, its an inbound message. If it goes out via SMTP, it's an outbound message. If its not inbound or outbound, it's internal.

0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...