Splunk Enterprise Security

How to get ta-mailclient setup?

csarte
New Member

We want to fetch emails from a mailbox and forward to splunk. I have the ta-mailclient installed on our HF Windows server. I went to Settings > Data inputs > Mail Server to add an Email account to monitor with protocol IMAP. No emails are being read.

GitHub - seunomosowon/TA-mailclient: This technology adapter add-on fetches emails for Splunk to ind...

Labels (2)
0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@csarte - Your starting point should be to look at the logs and see what is the error to further troubleshoot.

index=_internal sourcetype=splunkd (component=ModularInputs OR component=ExecProcessor) mail.py

 

I hope this helps, kindly upvote if it does!!!

0 Karma
Get Updates on the Splunk Community!

Splunk Answers Content Calendar, July Edition I

Hello Community! Welcome to another month of Community Content Calendar series! For the month of July, we will ...

Secure Your Future: Mastering Upgrade Readiness for Splunk 10

Spotlight: The Splunk Health Assistant Add-On  The Splunk Health Assistant Add-On is your ultimate companion ...

Observability Unlocked: Kubernetes & Cloud Monitoring with Splunk IM

Ready to master Kubernetes and cloud monitoring like the pros? Join Splunk’s Growth Engineering team on ...