Reporting

How to monitor Zimbra mail?

leenguyen07
Explorer

Step by step, I have Zimbra server with ip 192.168.1.2 and Splunk with ip 192.168.1.10. How do I configure Splunk to monitor Zimbra mail?

Tags (3)
0 Karma

dgrubb_splunk
Splunk Employee
Splunk Employee

Identify the Zimbra log data you want to monitor.

Use a Splunk Universal Forwarder to monitor the log files and send the data to your Splunk indexer.

Using the Splunk documentation: Getting Data in

http://docs.splunk.com/Documentation/Splunk/6.3.1/Data/WhatSplunkcanmonitor

to assist in in properly source-typing the ingested data ensuring for proper time-stamping and event breaking.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...