Brightmail¶
Key facts¶
- MSG Format based filter
- Legacy BSD Format default port 514
Links¶
Ref | Link |
---|---|
Splunk Add-on | TBD |
Product Manual | https://support.symantec.com/us/en/article.howto38250.html |
Sourcetypes¶
sourcetype | notes |
---|---|
symantec:smg | Requires version TA 3.6 |
Sourcetype and Index Configuration¶
key | sourcetype | index | notes |
---|---|---|---|
symantec_brightmail | symantec:smg | none |
Options¶
Variable | default | description |
---|---|---|
SC4S_SOURCE_FF_SYMANTEC_BRIGHTMAIL_GROUPMSG | yes | Email processing events generated by the bmserver process will be grouped by host+program+pid+msg ID into a single event |
SC4S_DEST_SYMANTEC_BRIGHTMAIL_SPLUNK_HEC_FMT | empty | if “JSON” and GROUPMSG is enabled format the event in json |
SC4S_DEST_SYMANTEC_BRIGHTMAIL_SYSLOG_FMT | empty | if “SDATA” and GROUPMSG is enabled format the event in rfc5424 sdata |