Reporting

Collect attachments in email as input.

JWBailey
Communicator

I have an application that is able to output data via attachments in email.

I am interested in collecting the data from those attachments into splunk. Is there an easy way to have splunk input the attachments? Nothing complex, the attachments are either CSV or XLS files.

I understand it is probably better to input via a different mechanism, but the application owner is hesitant to make changes to the current system.

Thank you,

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I had a similar problem and solved it by writing a scripted input that used the Office365 REST API to read emailed attachments. If you don't use Office365 then you may be able to use the IMAP Mailbox app.

---
If this reply helps you, Karma would be appreciated.
0 Karma

vmicovic2
Explorer

same here...

0 Karma

midwest_mexican
New Member

do you have code to share to you used to do this? I'm running into the same issue.

0 Karma

Smith_Splunk
Explorer

Hi All,

I have the similar use case, But IMAP app won't support reading attachment.
Does any one know the steps to proceed on this.

Thanks,
Smith

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...