Splunk® App for Microsoft Exchange (EOL)

Deploy and Use the Splunk App for Microsoft Exchange

Acrobat logo Download manual as PDF


On October 22 2021, the Splunk App for Microsoft Exchange will reach its end of life. After this date, Splunk will no longer maintain or develop this product. The functionality in this app is migrating to a content pack in Data Integrations. Learn about the Content Pack for Microsoft Exchange.
This documentation does not apply to the most recent version of Splunk® App for Microsoft Exchange (EOL). For documentation on the most recent version, go to the latest release.
Acrobat logo Download topic as PDF

Install a universal forwarder on each Exchange server

To get data from the Exchange servers into the Splunk App for Microsoft Exchange, you must install a Splunk universal forwarder onto each Exchange server in your environment, place the appropriate Splunk App for Microsoft Exchange add-ons into the forwarder, and configure the forwarders to send data to the central Splunk App for Microsoft Exchange instance.

You must also perform the same steps to get data from the Active Directory and Windows servers in your network. The only differences are the add-ons you install.

To install a universal forwarder onto each server, follow the steps located in one of these topics in the core Splunk Enterprise documentation:

Caution: Do not install a full Splunk instance on an Exchange server. Both full Splunk and Exchange have resource requirements that preclude installation of both services on one computer.

Once you've installed the universal forwarders, you can proceed to deploying the appropriate Splunk App for Microsoft Exchange add-ons to each one.

For more information about distributed deployments and how to deploy universal forwarders, read "Universal forwarder deployment overview" in the core Splunk Enterprise documentation.

Last modified on 19 April, 2014
PREVIOUS
How to deploy the Splunk App for Microsoft Exchange
  NEXT
Enable auditing and local PowerShell script execution on Active Directory and Exchange servers

This documentation applies to the following versions of Splunk® App for Microsoft Exchange (EOL): 3.0, 3.0.1, 3.0.2, 3.0.3


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters