Deploy and Use the Splunk App for Microsoft Exchange

 


What a Splunk App for Microsoft Exchange deployment looks like

This documentation does not apply to the most recent version of MSExchange. Click here for the latest version.

What a Splunk App for Microsoft Exchange deployment looks like

This topic discusses the overall architecture of a Splunk App for Microsoft Exchange deployment.

Overview

At a minimum, the Splunk App for Microsoft Exchange is made up of a "central" Splunk instance (containing the index and running Splunk Web that users will access to view the app) and some number of universal forwarders--one for each Exchange server you want to include in the deployment.

Each of the universal forwarders is configured with a Splunk for Microsoft Exchange technology add-on that collects the data for the Exchange server role(s) performed by the Exchange server it is running on. This data is forwarded to the central Splunk instance that is running the app.

About the Splunk for Microsoft Exchange technology add-ons

New for version 1.1 of the Splunk App for Microsoft Exchange, all forwarder application components have been replaced with technology add-ons (TAs).

Each TA is a folder that contains files needed by the Splunk App for Microsoft Exchange to transform data for a specific Exchange server role. The TA is specific to the Splunk App for Microsoft Exchange. Each TA is named according to the Exchange version and server role that it was designed for, and all begin with TA-.

The TAs are located within %SPLUNK_HOME%\etc\apps\Splunk_for_Exchange\appserver\addons.

Example Deployment

Typicalsplunkmse.11.png

This documentation applies to the following versions of MSExchange: 1.1 , 1.1.1 , 1.1.4 , 1.1.5 , 1.1.6 View the Article History for its revisions.


Comments

Hi Mkeys,

The fwd_apps.zip file is a part of version 1.0 of the Splunk App for Microsoft Exchange. Version 1.1 does not have this file.

Malmoore, Splunker
March 22, 2012

"The TAs are located within %SPLUNK_HOME%\etc\apps\Splunk_for_Exchange\appserver\addons" should read "The TAs are located within %SPLUNK_HOME%\etc\apps\Splunk_for_Exchange\appserver\static\fwd_apps.zip" now.

Mkeys
March 22, 2012

You must be logged into splunk.com in order to post comments. Log in now.

Was this documentation topic helpful?

If you'd like to hear back from us, please provide your email address:

We'd love to hear what you think about this topic or the documentation as a whole. Feedback you enter here will be delivered to the documentation team.

Feedback submitted, thanks!