Reporting

What is the best way to ingest links from the body of emails O365 Exchange or Mimecast?

benwebsternucle
Engager

I am currently ingesting O365 Exchange and Mimecast logs in to Splunk, but I would like to start ingesting any links that are contained in the body of emails to allow additional security checks. Has anyone come across a good way to achieve this?

Thanks

Labels (1)
0 Karma
1 Solution

nickhills
Ultra Champion

I have done this in the past with MimeCast - I don't think the MimeCast TA supported this, so I wrote a script to pull the message content in from the API.

https://www.mimecast.com/tech-connect/documentation/endpoint-reference/archive/get-message-detail/

If my comment helps, please give it a thumbs up!

View solution in original post

0 Karma

nickhills
Ultra Champion

I have done this in the past with MimeCast - I don't think the MimeCast TA supported this, so I wrote a script to pull the message content in from the API.

https://www.mimecast.com/tech-connect/documentation/endpoint-reference/archive/get-message-detail/

If my comment helps, please give it a thumbs up!
0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...