# ElasticMARC - DMARC Aggregate Report Analysis

**URL:** <https://discuss.elastic.co/t/elasticmarc-dmarc-aggregate-report-analysis/125044>\
**Category:** Community Ecosystem\
**Created:** [March 21, 2018, 5:06pm UTC](https://discuss.elastic.co/t/elasticmarc-dmarc-aggregate-report-analysis/125044 "2018-03-21T17:06:00Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [March 21, 2018, 5:06pm UTC](https://discuss.elastic.co/t/elasticmarc-dmarc-aggregate-report-analysis/125044/1 "2018-03-21T17:06:00Z")

</div>

Here's a solution I developed to ingest DMARC Aggregate reports. It's primarily aimed at Windows but if someone wants to collaborate to get the PowerShell functions ported into an OS agnostic language or a separate process that works on Linux, let me know.

> **[wwalker0307/ElasticMARC](https://github.com/wwalker0307/ElasticMARC)**
>
> ElasticMARC - DMARC Aggregate report digest and analysis for Windows utilizing the Elastic Stack

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 21, 2018, 7:56pm UTC](https://discuss.elastic.co/t/elasticmarc-dmarc-aggregate-report-analysis/125044/2 "2018-03-21T19:56:36Z")

</div>

Awesome stuff, thanks for sharing this!

I note that you say there is no installer for the stack, which is correct, but have you seen the Elasticsearch MSI installer?

---

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [March 21, 2018, 8:33pm UTC](https://discuss.elastic.co/t/elasticmarc-dmarc-aggregate-report-analysis/125044/3 "2018-03-21T20:33:27Z")

</div>

> [@wwalker](#):
>
> Here's a solution I developed to ingest DMARC Aggregate reports. It's primarily aimed at Windows but if someone wants to collaborate to get the PowerShell functions ported into an OS agnostic language or a separate process that works on Linux, let me know.
> 
> [GitHub - wwalker0307/ElasticMARC: DMARC Aggregate report digest and analysis for Windows utilizing the Elastic Stack](https://github.com/wwalker0307/ElasticMARC)

lol, does seeing the download link count? I was aware when I wrote the guide that the MSI for Elasticsearch existed, but I was trying to keep the guide simple and, since I never used it, I wasn't aware of the process. I also thought it might start getting muddy and/or confusing if I tried to explain all the different ways you could install the different applications.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 21, 2018, 8:40pm UTC](https://discuss.elastic.co/t/elasticmarc-dmarc-aggregate-report-analysis/125044/4 "2018-03-21T20:40:15Z")

</div>

Yeah, makes sense 🙂

---

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [April 5, 2018, 5:51am UTC](https://discuss.elastic.co/t/elasticmarc-dmarc-aggregate-report-analysis/125044/5 "2018-04-05T05:51:53Z")

</div>

Just realized I have this posted in the wrong sub-forum. Can a mod move it to the appropriate place?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [April 5, 2018, 6:17am UTC](https://discuss.elastic.co/t/elasticmarc-dmarc-aggregate-report-analysis/125044/6 "2018-04-05T06:17:07Z")

</div>

Where do you want to move it? In #annoucements:community-ecosystem

---

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [April 5, 2018, 2:15pm UTC](https://discuss.elastic.co/t/elasticmarc-dmarc-aggregate-report-analysis/125044/7 "2018-04-05T14:15:20Z")

</div>

I was thinking Ecosystem was the appropriate place, is that wrong?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [April 5, 2018, 2:55pm UTC](https://discuss.elastic.co/t/elasticmarc-dmarc-aggregate-report-analysis/125044/8 "2018-04-05T14:55:21Z")

</div>

I moved it. LMK if it's not ok.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 12, 2018, 10:24am UTC](https://discuss.elastic.co/t/elasticmarc-dmarc-aggregate-report-analysis/125044/10 "2018-07-12T10:24:36Z")

</div>


