Reporting

maildir indexing?

jtrucks
Splunk Employee
Splunk Employee

Has anyone indexed maildir formatted email archives/folders before? I'm thinking this might be crazy but useful to ingest my archived mail, which is all on local disk on the system running Splunk.

Thoughts? Ideas?

--
Jesse Trucks
Minister of Magic
Tags (3)
1 Solution

jtrucks
Splunk Employee
Splunk Employee

Turns out that Splunk will read Maildir trees just fine. With some transform magic you can get all the fields to work, as well.

--
Jesse Trucks
Minister of Magic

View solution in original post

0 Karma

jtrucks
Splunk Employee
Splunk Employee

Turns out that Splunk will read Maildir trees just fine. With some transform magic you can get all the fields to work, as well.

--
Jesse Trucks
Minister of Magic
0 Karma

eashwar
Communicator

hi jtrucks

is this what you are looking for

http://blogs.splunk.com/2011/01/07/splunk-sysadmin-email/

0 Karma

jtrucks
Splunk Employee
Splunk Employee

I don't know what the tacotacotaco stuff is for, but perhaps I could point Splunk just at the maildir and see what happens...

--
Jesse Trucks
Minister of Magic
0 Karma

jtrucks
Splunk Employee
Splunk Employee

So, this is similar, but not quite it as I am thinking of full mail parsing for random email:

http://splunk-base.splunk.com/answers/61093/how-can-i-convert-mailbox-or-maildir-to-splunk

--
Jesse Trucks
Minister of Magic
0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...