Reporting

Can Ironport Mail logs remain local to appliance and be in Splunk?

sdrewis
New Member

I am looking into adding our Ironport mail logs into Splunk. I tried out this solution about a year and a half ago and noticed that the Ironport appliances do not retain any logs locally after it is connected up to Splunk. This will remove some functionality of the Ironport Management appliance.

Does anybody know if the newer versions allow the appliances to retain their local logs so we can have reporting in Splunk as well as the appliances? I am afraid to test out the app again and lose mail logs on the appliances.

Tags (1)
0 Karma

chuffaker
New Member

We've seen the same behavior. If you send mail_logs to Splunk they will not be retained on the Ironport Management appliance.

Any workarounds?

0 Karma

dart
Splunk Employee
Splunk Employee

I've not used Ironport in a while, but when I last did this you could add additional log subscriptions, and that's how I added the data to Splunk. How are you configuring the mail logs to reach Splunk?

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...