Reporting

Can Ironport Mail logs remain local to appliance and be in Splunk?

sdrewis
New Member

I am looking into adding our Ironport mail logs into Splunk. I tried out this solution about a year and a half ago and noticed that the Ironport appliances do not retain any logs locally after it is connected up to Splunk. This will remove some functionality of the Ironport Management appliance.

Does anybody know if the newer versions allow the appliances to retain their local logs so we can have reporting in Splunk as well as the appliances? I am afraid to test out the app again and lose mail logs on the appliances.

Tags (1)
0 Karma

chuffaker
New Member

We've seen the same behavior. If you send mail_logs to Splunk they will not be retained on the Ironport Management appliance.

Any workarounds?

0 Karma

dart
Splunk Employee
Splunk Employee

I've not used Ironport in a while, but when I last did this you could add additional log subscriptions, and that's how I added the data to Splunk. How are you configuring the mail logs to reach Splunk?

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...