Monitoring Splunk

Splunk Cloud email monitoring

kevinmarkley198
New Member

Hello,

I would like to set up splunk cloud (vs 7) to accept emails as events.

Tags (2)
0 Karma

nickhills
Ultra Champion

Splunk does not have an endpoint for receiving emails. You can not send emails directly to Splunk.
Also - do you need just message metadata or the full body? - If latter think carefully about privacy concerns, and index security.

With that said:

You can get email data into Splunk, but the hard part is getting it somewhere else first.
Your approach very much depends on what your email architecture is at the moment.

If you have cloud hosted email, you need to establish if there is an API method to directly retrieve emails for a given user/mailbox possibly via an export or DLP interface (most free/basic/medium packages don't offer this)

If you self host your email service, you may be able to use a journaling process to take a copy of the relevant mails into a dedicated journaling mailbox. You could then use a mail client to read and output the messages to a filesystem, and then use an HF to collect the email data and send it to Splunk.

If you have 3rd party DLP/AV/Filtering services/gateways you may be able to obtain logs from them. Some allow the content of the message body to be revealed, some do not. This is probably the best approach if its available to you.

You should start off by establishing what access you can get to the email data (Not a Splunk Problem) and then once you can access it figure out how to ingest it into Splunk with a HF.

If my comment helps, please give it a thumbs up!
0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...