Skip to content

Brightmail

Key facts

  • MSG Format based filter
  • Legacy BSD Format default port 514
Ref Link
Splunk Add-on TBD
Product Manual https://support.symantec.com/us/en/article.howto38250.html

Sourcetypes

sourcetype notes
symantec:smg Requires version TA 3.6

Sourcetype and Index Configuration

key sourcetype index notes
symantec_brightmail symantec:smg email none

Options

Variable default description
SC4S_SOURCE_FF_SYMANTEC_BRIGHTMAIL_GROUPMSG yes Email processing events generated by the bmserver process will be grouped by host+program+pid+msg ID into a single event
SC4S_DEST_SYMANTEC_BRIGHTMAIL_SPLUNK_HEC_FMT empty if “JSON” and GROUPMSG is enabled format the event in json
SC4S_DEST_SYMANTEC_BRIGHTMAIL_SYSLOG_FMT empty if “SDATA” and GROUPMSG is enabled format the event in rfc5424 sdata