Splunk® App for Microsoft Exchange (EOL)

Deploy and Use the Splunk App for Microsoft Exchange

On October 22 2021, the Splunk App for Microsoft Exchange will reach its end of life. After this date, Splunk will no longer maintain or develop this product. The functionality in this app is migrating to a content pack in Data Integrations. Learn about the Content Pack for Microsoft Exchange.
This documentation does not apply to the most recent version of Splunk® App for Microsoft Exchange (EOL). For documentation on the most recent version, go to the latest release.

Install a universal forwarder on each Exchange server

Splunk forwarders are configured to send data to a central Splunk instance, which then indexes the data for use in searches and analysis. Before you can use the Splunk App for Microsoft Exchange, you must install a universal forwarder on each of the Microsoft Exchange servers you want to include in your Splunk App for Exchange deployment.

Start with the information in "Universal forwarder deployment overview" in the core Splunk documentation and then pick the relevant topic later in the same chapter for the specific instructions you need based on your environment.

Once you've installed the universal forwarders, you can proceed to deploying the relevant Splunk App for Microsoft Exchange components to each one.

Caution: Do not install a full Splunk instance on an Exchange server. Both full Splunk and Exchange have resource requirements that preclude installation of both services on one computer.

Last modified on 01 October, 2012
How to deploy the Splunk App for Microsoft Exchange   Make configuration changes to match your existing environment

This documentation applies to the following versions of Splunk® App for Microsoft Exchange (EOL): 1.1, 1.1.1, 1.1.4, 1.1.5, 1.1.6








You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters