Getting Data In

How to monitor Windows SMTP relay data to find rejections?

brent_weaver
Builder

My team and I are integrating our monitoring tools into our ticketing system. To open a ticket I need to email a specific address, and if the format of the email is one char off, or there is a config item that does not exist, it will drop and and nothing will get done. So I turn to splunk 🙂

How can I log on my Windows smtp relay server to detect such events, and for that matter all events!

Thanks!

0 Karma

bryan_dady
Explorer

Have you enabled SMTP Logging in your IIS configs?
If so, you can point your forwarders to index those logs, and then search them.

0 Karma

s2_splunk
Splunk Employee
Splunk Employee

Have you taken a closer look at the Splunk App for Exchange? I am not familiar with how the Windows SMTP relay server logs, so it's hard to answer your specific question.
An alternative approach may be to use the Splunk App for Stream, which supports smtp protocol analysis in Splunk directly off the wire.

0 Karma
Get Updates on the Splunk Community!

Index This | What did the zero say to the eight?

June 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this month’s ...

Splunk Observability Cloud's AI Assistant in Action Series: Onboarding New Hires & ...

This is the fifth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Now Playing: Splunk Education Summer Learning Premieres

It’s premiere season, and Splunk Education is rolling out new releases you won’t want to miss. Whether you’re ...