Splunk Search

Email Delivery

NamoSiddhanam
Loves-to-Learn

HI,

Splunk is a new tool to me, so I apologize for the very basic question. 

Could you please provide a query that includes email delivery status with reason, or detailed information if delivered/not delivered, as well as multiple specific subject sources from Postfix?

Labels (1)
0 Karma

yuanliu
SplunkTrust
SplunkTrust

This question has very little to do with Splunk or your familiarity with Splunk.  As @PickleRick suggested, the first most important question is: What data source do you have in Splunk?

The real question you need to ask is: How do I, without Splunk, determine from A source that has been ingested into Splunk "email delivery status with reason, or detailed information if delivered/not delivered, as well as multiple specific subject sources from Postfix?"  This is a data analytics forum, not a Postfix or a Linux forum.  But there is more to a search.  You need also to ask yourself: Which Email am I searching for?

Assume your Splunk instance contains syslog entries from Postfix, you can determine delivery status if the recipient is known (better, if both sender and recipients are known) as well as the approximate time of that Email.  No, a typical postfix configuration does not include subject in logs.  So searching for subject is futile.  Also note: Modern syslog can use different log formats.  Which one does your system use?

If you can post answers to these questions you ask yourself, volunteers here can help you construct a meaningful search.  Or you may have found the search when trying to answer those questions.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

1. Are you sure you even have such data in your Splunk? (and have access to it)

2. Email logs are typically a pain to work with since information about a single message is usually spread across a whole lot of events, often changing identifiers for the message as it goes through various stages of email processing. This includes Postfix - it can pass the message back and forth between different components and if you have amavis or external spamd in the mix... boy, you're in for a treat.

3. Unless you do something non-standard with your logging, email daemons like postfix, sendmail or exim do _not_ contain info from within the message (like subject). They typically only have the envelope info.

 

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...