Mimecast for Splunk

Add Mimecast data to your Splunk environment.

Developed by Mimecast
Support contact Mimecast
Documentation Administrators Guide
Download SplunkBase

Overview

This app provides an easy way to add Mimecast gateway and audit events into your Splunk Enterprise environment, as well as a number of predefined dashboards to give you valuable, actionable insights into your organization's email security.

Mimecast for Splunk Simple Dashboard

Release notes

Current version: 2.0.1

  • Added support and dashboards for new Targeted Threat Protection URL Protect and Attachment Protect data types.
  • Refreshed version 1 dashboards to be more efficient and moved these to the Sample Dashboards menu.
  • Added support for proxy settings in the modular input script.
  • Added support for Advanced Account Administration customers to access log data from all their accounts using a single installation of the app.
  • Changed logging strategy of the modular input script from logging to file to logging to the splunkd log
  • Added a new Troubleshooting dashboard to get easy access and display logs.
  • Simplified app configuration and programatic extraction of the access key and secret key values required to authorize API requests.
  • Added support for rate limiting applied by the Mimecast API.
  • Removed requirement on version 1 of the Mimecast API.
  • Improved error handling.

Previous version: 1.0.4

  • Adds support for secure storage for Mimecast Access and Secret Keys
  • Addresses an issue where check point files were not being closed properly