TA-Symantec Mail Gateway

Splunk Community

TA-Symantec Mail Gateway

TA-Symantec Mail Gateway
This Splunk Technology Add-on (TA) enables parsing and normalization of logs from Symantec Mail Gateway (SMG) systems. It extracts structured fields from raw syslog data and assigns appropriate sourcetypes for accurate categorization and analysis in Splunk and assign sourcetype=symantec:mg:syslog, as default to all the incoming data. The TA supports multiple components of Symantec Mail Gateway including: bmserver – Verdicts, TrackerIDs, Attachments, Quarantine actions ecelerity – Email delivery, ORCPTS, TRACKERID, TRANS_FAILURE, DELIVERY_FAILURE audit – Quarantine Delete/Release events quarantine – Spam quarantine summary logs brightmail – Watchdog, URLAnalyzer, Spamhunter dns – Named (BIND) resolver responses system – CROND, rsyslogd-pstats, cron jobs mail – Message views by users (AuditEventLogManager) auth – Sudo session opens/closes syslog – Miscellaneous default logs.
0 topics and 0 replies mentioned TA-Symantec Mail Gateway in
Latest Topics
No posts to display.
Latest Replies
No posts to display.
Top Topics
No posts to display.
My Topics
No posts to display.