We have previously used the Splunk TA-mail client Add-on (with a minor modification to input email from MS Exchange):
https://splunkbase.splunk.com/app/3200
Latest version was released Nov 2017, and supports up to Splunk 7.0 (but has incompatibilities with Splunk 7.1.x ++)
After we upgraded to Splunk 7.1, the Add-on stopped working, no longer indexed email . . . and noticed that:
The view for App configuration is blank / broken
Differences in password.conf implementations
Modular input and python configuration / code
How to make this app working for the higher versions of the TA mail client app?
... View more