Reporting

maildir indexing?

jtrucks
Splunk Employee
Splunk Employee

Has anyone indexed maildir formatted email archives/folders before? I'm thinking this might be crazy but useful to ingest my archived mail, which is all on local disk on the system running Splunk.

Thoughts? Ideas?

--
Jesse Trucks
Minister of Magic
Tags (3)
1 Solution

jtrucks
Splunk Employee
Splunk Employee

Turns out that Splunk will read Maildir trees just fine. With some transform magic you can get all the fields to work, as well.

--
Jesse Trucks
Minister of Magic

View solution in original post

0 Karma

jtrucks
Splunk Employee
Splunk Employee

Turns out that Splunk will read Maildir trees just fine. With some transform magic you can get all the fields to work, as well.

--
Jesse Trucks
Minister of Magic
0 Karma

eashwar
Communicator

hi jtrucks

is this what you are looking for

http://blogs.splunk.com/2011/01/07/splunk-sysadmin-email/

0 Karma

jtrucks
Splunk Employee
Splunk Employee

I don't know what the tacotacotaco stuff is for, but perhaps I could point Splunk just at the maildir and see what happens...

--
Jesse Trucks
Minister of Magic
0 Karma

jtrucks
Splunk Employee
Splunk Employee

So, this is similar, but not quite it as I am thinking of full mail parsing for random email:

http://splunk-base.splunk.com/answers/61093/how-can-i-convert-mailbox-or-maildir-to-splunk

--
Jesse Trucks
Minister of Magic
0 Karma
Get Updates on the Splunk Community!

Wrapping Up Cybersecurity Awareness Month

October might be wrapping up, but for Splunk Education, cybersecurity awareness never goes out of season. ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...

What's New in Splunk Observability - October 2025

What’s New?    We’re excited to announce the latest enhancements to Splunk Observability Cloud and share ...