Monitoring Splunk

Splunk Cloud email monitoring

kevinmarkley198
New Member

Hello,

I would like to set up splunk cloud (vs 7) to accept emails as events.

Tags (2)
0 Karma

nickhills
Ultra Champion

Splunk does not have an endpoint for receiving emails. You can not send emails directly to Splunk.
Also - do you need just message metadata or the full body? - If latter think carefully about privacy concerns, and index security.

With that said:

You can get email data into Splunk, but the hard part is getting it somewhere else first.
Your approach very much depends on what your email architecture is at the moment.

If you have cloud hosted email, you need to establish if there is an API method to directly retrieve emails for a given user/mailbox possibly via an export or DLP interface (most free/basic/medium packages don't offer this)

If you self host your email service, you may be able to use a journaling process to take a copy of the relevant mails into a dedicated journaling mailbox. You could then use a mail client to read and output the messages to a filesystem, and then use an HF to collect the email data and send it to Splunk.

If you have 3rd party DLP/AV/Filtering services/gateways you may be able to obtain logs from them. Some allow the content of the message body to be revealed, some do not. This is probably the best approach if its available to you.

You should start off by establishing what access you can get to the email data (Not a Splunk Problem) and then once you can access it figure out how to ingest it into Splunk with a HF.

If my comment helps, please give it a thumbs up!
0 Karma
Get Updates on the Splunk Community!

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...