Reporting

Can Ironport Mail logs remain local to appliance and be in Splunk?

sdrewis
New Member

I am looking into adding our Ironport mail logs into Splunk. I tried out this solution about a year and a half ago and noticed that the Ironport appliances do not retain any logs locally after it is connected up to Splunk. This will remove some functionality of the Ironport Management appliance.

Does anybody know if the newer versions allow the appliances to retain their local logs so we can have reporting in Splunk as well as the appliances? I am afraid to test out the app again and lose mail logs on the appliances.

Tags (1)
0 Karma

chuffaker
New Member

We've seen the same behavior. If you send mail_logs to Splunk they will not be retained on the Ironport Management appliance.

Any workarounds?

0 Karma

dart
Splunk Employee
Splunk Employee

I've not used Ironport in a while, but when I last did this you could add additional log subscriptions, and that's how I added the data to Splunk. How are you configuring the mail logs to reach Splunk?

0 Karma
Get Updates on the Splunk Community!

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...