Reporting

Can Ironport Mail logs remain local to appliance and be in Splunk?

sdrewis
New Member

I am looking into adding our Ironport mail logs into Splunk. I tried out this solution about a year and a half ago and noticed that the Ironport appliances do not retain any logs locally after it is connected up to Splunk. This will remove some functionality of the Ironport Management appliance.

Does anybody know if the newer versions allow the appliances to retain their local logs so we can have reporting in Splunk as well as the appliances? I am afraid to test out the app again and lose mail logs on the appliances.

Tags (1)
0 Karma

chuffaker
New Member

We've seen the same behavior. If you send mail_logs to Splunk they will not be retained on the Ironport Management appliance.

Any workarounds?

0 Karma

dart
Splunk Employee
Splunk Employee

I've not used Ironport in a while, but when I last did this you could add additional log subscriptions, and that's how I added the data to Splunk. How are you configuring the mail logs to reach Splunk?

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...