Monitoring Splunk

monitored drafted mail

praneshjan
Explorer

We are using Zimbra as our private mail server. We are monitoring the logs of this server. How can I see if someone has saved any attachment in draft? Which log indicated the attachment in draft. Please help.

0 Karma

kevinwdunn
New Member

I don't believe there is going to be a logfile to monitor. If there is a logfile to be found, your question should be asked on zimbra forums as the people on there may know if that logfile exists can exist in a logfile by modifying something with zmcontrol or something like that.

Personally, my approach to this problem would be to create a script to login to every mailbox, and look at every message in the drafts folder of every mailbox, output desired meta data information to Splunk HEC or local logfile to be consumed by splunk forwarder. Essentially you need a middle ware tier (or custom splunk app) to generate the information that you're looking to obtain from the mailbox to feed into Splunk.

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...