Overview Monitoring mail outbound (egress) using Splunk isn’t as straight forward as you might think. I’ve put together a nice search string that will help identify egress email from an Ubuntu server.
How to Install and Configure Splunk on Linux
Splunk is a software package for sending logs from a variety of server types or devices to a centralised repository for the ability to do searching, monitoring and analyzing of big data using a web style interface console. This Example In this example I will be installing Splunk version 6.0 on a virtualised Linux Debian… Read more »