All Apps and Add-ons

how can capture smtp by splunk stream

satorn_ja
New Member

I set up my server to be mail server, splunk search head, splunk indexer and splunk TA-stream.
After installation i enable smtp on stream config page then try to send/receive e-mail.
I use "source=stream*" on search page, There are no any result on "sourcetyp=stream:smtp"

Tags (1)
0 Karma

vshcherbakov_sp
Splunk Employee
Splunk Employee

Hi satorn_ja,

Did you check if the Wire Data Input is enabled/working on your server? When you install splunk_app_stream, it drops Splunk_TA_stream on your server, but doesn't enable it by default. You can check status/enable it if you to Settings->Data Inputs -> Wire Data.

Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...