Splunk Enterprise Security

How to get ta-mailclient setup?

csarte
New Member

We want to fetch emails from a mailbox and forward to splunk. I have the ta-mailclient installed on our HF Windows server. I went to Settings > Data inputs > Mail Server to add an Email account to monitor with protocol IMAP. No emails are being read.

GitHub - seunomosowon/TA-mailclient: This technology adapter add-on fetches emails for Splunk to ind...

Labels (2)
0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@csarte - Your starting point should be to look at the logs and see what is the error to further troubleshoot.

index=_internal sourcetype=splunkd (component=ModularInputs OR component=ExecProcessor) mail.py

 

I hope this helps, kindly upvote if it does!!!

0 Karma
Get Updates on the Splunk Community!

Splunk App Dev Community Updates – What’s New and What’s Next

Welcome to your go-to roundup of everything happening in the Splunk App Dev Community! Whether you're building ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco + Splunk! We’ve ...

Enterprise Security Content Update (ESCU) | New Releases

In April, the Splunk Threat Research Team had 2 releases of new security content via the Enterprise Security ...