Hi All,
Been working at getting the exchange app installed and having issues with this one TA-Exchange-Mailbox and Exchange Server 2010.
http://docs.splunk.com/Documentation/MSExchange/3.4.2/A...
I have the Microsoft 365 App for Splunk installed and most of our panels have data. The only one that does not is the "Mailbox Migration" panel under Exchange Overview. Seems the panel is looking f...
Hi all,
is there a way to integrate with O365 and, given a malicious email (identified by subject and sender), search for it in all the mailboxes of all the users and then delete it?
I was l...
I have two mailboxes I want to monitor. It's fine for the email events to go into the same index. Is it possible to add a second IMAP configuration to imap.conf?
For example:
[IMAP C...
Hi,
I'm trying to setup the IMAP Mailbox App. When I'm running the get_imap_mail.py from the CLI, I can see all the emails present in the mailbox, but it doesn't index. When I looked at the s...
Is Splunk able to collect exchange 2010 mailbox audit logs from each mailbox and how? The mailbox audit logs are written within each application and stored on each mailbox. Since the mailbox audit l...
Once the IMAP Mailbox app retrieves an email from the server, does the app delete the email from the in-box? If so, is this configurable to any degree? i.e. all/none delete or delete only from c...
we have one audit point that non owner users like domain admin, exchange admin's are opening other's mailboxes and there is no check.
which option need to enable to get the logs from exchange t...
Hi, trying to get this this working on windows. Put in the basic for the imap.conf I get the error below by directly running
1) splunk envvars
2) splunk cmd python "D:\Program Files\Splunk\etc...