Reporting

maildir indexing?

jtrucks
Splunk Employee
Splunk Employee

Has anyone indexed maildir formatted email archives/folders before? I'm thinking this might be crazy but useful to ingest my archived mail, which is all on local disk on the system running Splunk.

Thoughts? Ideas?

--
Jesse Trucks
Minister of Magic
Tags (3)
1 Solution

jtrucks
Splunk Employee
Splunk Employee

Turns out that Splunk will read Maildir trees just fine. With some transform magic you can get all the fields to work, as well.

--
Jesse Trucks
Minister of Magic

View solution in original post

0 Karma

jtrucks
Splunk Employee
Splunk Employee

Turns out that Splunk will read Maildir trees just fine. With some transform magic you can get all the fields to work, as well.

--
Jesse Trucks
Minister of Magic
0 Karma

eashwar
Communicator

hi jtrucks

is this what you are looking for

http://blogs.splunk.com/2011/01/07/splunk-sysadmin-email/

0 Karma

jtrucks
Splunk Employee
Splunk Employee

I don't know what the tacotacotaco stuff is for, but perhaps I could point Splunk just at the maildir and see what happens...

--
Jesse Trucks
Minister of Magic
0 Karma

jtrucks
Splunk Employee
Splunk Employee

So, this is similar, but not quite it as I am thinking of full mail parsing for random email:

http://splunk-base.splunk.com/answers/61093/how-can-i-convert-mailbox-or-maildir-to-splunk

--
Jesse Trucks
Minister of Magic
0 Karma
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...