Getting Data In

Email Input

cjaramilloc
Explorer

Hello Splunkers,

I'm wondering the best way to index an email. Not email server logs, the actual mail.

There are a couple apps that maybe help with this but they are very old:

https://splunkbase.splunk.com/app/3200/

https://splunkbase.splunk.com/app/1739/

Has anyone already did this? Any advice?

Christian

Tags (2)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

at least IMAPMailbox is working with splunk 7.3.x, but not anymore whit splunk 8 without rewriting it to support python 3.

r. Ismo

0 Karma

cjaramilloc
Explorer

I'm using Splunk 8. That's why I need an updated solution. 😕

0 Karma

isoutamo
SplunkTrust
SplunkTrust

One “temporary” solution is set up a HF (with 7.3.x) where run this until someone get better solution. 
r. Ismo

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...

Get Early Access to AI Playbook Authoring: Apply for the Alpha Private Preview ...

Passionate about security automation? Apply now to our AI Playbook Authoring Alpha private preview ...

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...