Monitoring Splunk

Splunk Cloud email monitoring

kevinmarkley198
New Member

Hello,

I would like to set up splunk cloud (vs 7) to accept emails as events.

Tags (2)
0 Karma

nickhills
Ultra Champion

Splunk does not have an endpoint for receiving emails. You can not send emails directly to Splunk.
Also - do you need just message metadata or the full body? - If latter think carefully about privacy concerns, and index security.

With that said:

You can get email data into Splunk, but the hard part is getting it somewhere else first.
Your approach very much depends on what your email architecture is at the moment.

If you have cloud hosted email, you need to establish if there is an API method to directly retrieve emails for a given user/mailbox possibly via an export or DLP interface (most free/basic/medium packages don't offer this)

If you self host your email service, you may be able to use a journaling process to take a copy of the relevant mails into a dedicated journaling mailbox. You could then use a mail client to read and output the messages to a filesystem, and then use an HF to collect the email data and send it to Splunk.

If you have 3rd party DLP/AV/Filtering services/gateways you may be able to obtain logs from them. Some allow the content of the message body to be revealed, some do not. This is probably the best approach if its available to you.

You should start off by establishing what access you can get to the email data (Not a Splunk Problem) and then once you can access it figure out how to ingest it into Splunk with a HF.

If my comment helps, please give it a thumbs up!
0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud's AI Assistant in Action Series: Auditing Compliance and ...

This is the third post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

What You Read The Most: Splunk Lantern’s Most Popular Articles!

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...