Getting Data In

Is there an app for Splunk that onboard data from mailboxes?

Loves-to-Learn Lots


I know there is an Exchange app for Splunk, and it covers a few different use cases, such as performance, usage, health, etc ... But ... is there an app which can actually onboard data from mailboxes, i.e., received/sent emails including metadata, attachments, body, headers, etc...?

Thank you.

0 Karma


TA-Exchange-Mailbox - AddOn-Exchange-Mailbox:(C:\Program Files\Microsoft\Exchange Server\V15\TransportRoles\Logs\MessageTracking]) This is the data input and field extractions for an Exchange Mailbox Role. It is used in conjunction with Splunk for Exchange.

There is add-on “Microsoft Office 365 Reporting Add-on for Splunk” available in Splunk base that collects Message Trace data from Microsoft Office 365.

0 Karma
Get Updates on the Splunk Community!

Splunk Security Content for Threat Detection & Response, Q1 Roundup

Join Principal Threat Researcher, Michael Haag, as he walks through:An introduction to the Splunk Threat ...

Splunk Life | Happy Pride Month!

Happy Pride Month, Splunk Community! 🌈 In the United States, as well as many countries around the ...

SplunkTrust | Where Are They Now - Michael Uschmann

The Background Five years ago, Splunk published several videos showcasing members of the SplunkTrust to share ...