Getting Data In

How to monitor Windows SMTP relay data to find rejections?

brent_weaver
Builder

My team and I are integrating our monitoring tools into our ticketing system. To open a ticket I need to email a specific address, and if the format of the email is one char off, or there is a config item that does not exist, it will drop and and nothing will get done. So I turn to splunk 🙂

How can I log on my Windows smtp relay server to detect such events, and for that matter all events!

Thanks!

0 Karma

bryan_dady
Explorer

Have you enabled SMTP Logging in your IIS configs?
If so, you can point your forwarders to index those logs, and then search them.

0 Karma

s2_splunk
Splunk Employee
Splunk Employee

Have you taken a closer look at the Splunk App for Exchange? I am not familiar with how the Windows SMTP relay server logs, so it's hard to answer your specific question.
An alternative approach may be to use the Splunk App for Stream, which supports smtp protocol analysis in Splunk directly off the wire.

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...