Getting Data In

How to monitor Windows SMTP relay data to find rejections?

brent_weaver
Builder

My team and I are integrating our monitoring tools into our ticketing system. To open a ticket I need to email a specific address, and if the format of the email is one char off, or there is a config item that does not exist, it will drop and and nothing will get done. So I turn to splunk 🙂

How can I log on my Windows smtp relay server to detect such events, and for that matter all events!

Thanks!

0 Karma

bryan_dady
Explorer

Have you enabled SMTP Logging in your IIS configs?
If so, you can point your forwarders to index those logs, and then search them.

0 Karma

s2_splunk
Splunk Employee
Splunk Employee

Have you taken a closer look at the Splunk App for Exchange? I am not familiar with how the Windows SMTP relay server logs, so it's hard to answer your specific question.
An alternative approach may be to use the Splunk App for Stream, which supports smtp protocol analysis in Splunk directly off the wire.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud's AI Assistant in Action Series: Auditing Compliance and ...

This is the third post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

What You Read The Most: Splunk Lantern’s Most Popular Articles!

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...