Splunk Enterprise Security

How to get ta-mailclient setup?

csarte
New Member

We want to fetch emails from a mailbox and forward to splunk. I have the ta-mailclient installed on our HF Windows server. I went to Settings > Data inputs > Mail Server to add an Email account to monitor with protocol IMAP. No emails are being read.

GitHub - seunomosowon/TA-mailclient: This technology adapter add-on fetches emails for Splunk to ind...

Labels (2)
0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@csarte - Your starting point should be to look at the logs and see what is the error to further troubleshoot.

index=_internal sourcetype=splunkd (component=ModularInputs OR component=ExecProcessor) mail.py

 

I hope this helps, kindly upvote if it does!!!

0 Karma
Get Updates on the Splunk Community!

Developer Spotlight with Brett Adams

In our third Spotlight feature, we're excited to shine a light on Brett—a Splunk consultant, innovative ...

Index This | What can you do to make 55,555 equal 500?

April 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Say goodbye to manually analyzing phishing and malware threats with Splunk Attack ...

In today’s evolving threat landscape, we understand you’re constantly bombarded with phishing and malware ...