Brightmail¶
Key facts¶
- MSG Format based filter
- Legacy BSD Format default port 514
Links¶
| Ref | Link | 
|---|---|
| Splunk Add-on | TBD | 
| Product Manual | https://support.symantec.com/us/en/article.howto38250.html | 
Sourcetypes¶
| sourcetype | notes | 
|---|---|
| symantec:smg | Requires version TA 3.6 | 
Sourcetype and Index Configuration¶
| key | sourcetype | index | notes | 
|---|---|---|---|
| symantec_brightmail | symantec:smg | none | 
Options¶
| Variable | default | description | 
|---|---|---|
| SC4S_SOURCE_FF_SYMANTEC_BRIGHTMAIL_GROUPMSG | yes | Email processing events generated by the bmserver process will be grouped by host+program+pid+msg ID into a single event | 
| SC4S_DEST_SYMANTEC_BRIGHTMAIL_SPLUNK_HEC_FMT | empty | if “JSON” and GROUPMSG is enabled format the event in json | 
| SC4S_DEST_SYMANTEC_BRIGHTMAIL_SYSLOG_FMT | empty | if “SDATA” and GROUPMSG is enabled format the event in rfc5424 sdata |