Splunk® App for Microsoft Exchange (EOL)

Deploy and Use the Splunk App for Microsoft Exchange

Acrobat logo Download manual as PDF


On October 22 2021, the Splunk App for Microsoft Exchange will reach its end of life. After this date, Splunk will no longer maintain or develop this product. The functionality in this app is migrating to a content pack in Data Integrations. Learn about the Content Pack for Microsoft Exchange.
This documentation does not apply to the most recent version of Splunk® App for Microsoft Exchange (EOL). For documentation on the most recent version, go to the latest release.
Acrobat logo Download topic as PDF

Release notes

This topic contains information on new features, known issues, and updates as we version the Splunk App and Technology Add-ons for Microsoft Exchange.

The latest version of the Splunk App for Microsoft Exchange was released on Monday, September 1, 2014.

What's new

Here's what's new in the latest version of the Splunk App for Microsoft Exchange:

  • Many bug fixes.
  • Several add-ons included with the app have been updated to fix bugs. (MSAPP-2482, MSAPP-2483)
  • A new server role exchange-admin has been added that makes it easier to grant permissions to Splunk users to search the Splunk App for Microsoft Exchange indexes. (MSAPP-2698)
  • The Host Performance page has been completely revamped and panels in the page have been relocated for ease of use and faster knowledge transfer. (MSAPP-2493)
  • The User Behavior Overview page has been split into two pages: One (User Behavior Overview) that shows the behavior of a single user, and another (Client Service Overview) that shows behavior of all users. (MSAPP-2511)
  • The Clustering and Replication page has been modified to allow cluster selection. Additionally, the Performance chart at the bottom of the page has been split into two and converted into stacked area charts instead of line charts. (MSAPP-2506)
  • A new panel has been added that lets you analyze the databases on a host at the drive level. (MSAPP-2778)
  • The Message Activity Overview page now allows you to review specifics on message activity when you click on a point in time on any of the graphs. (MSAPP-2510)
  • The SMTP Reputation panel now resides at the top of the Message Activity Overview page. (MSAPP-2508)
  • The Windows Updates & Downtime page has been reorganized to display information based on Exchange server roles. (MSAPP-2507)
  • The Analyze a Mailbox / Host pages have had search efficiency improvements. (MSAPP-2501)
  • The Analyze a Mailbox Database page now allows you to see information about the backup history, database size growth, and log growth for a particular database. (MSAPP-2503, MSAPP-2504)
  • The Mailbox Disk Space Used panel in the Analyze a Host page now allows you to analyze the mailbox growth in more detail, including the ability to see lists of the largest and quickest growing mailboxes as well as a detail of mailbox folders for users that appear in those lists. (MSAPP-2502)
  • The Anomalous Logins reports now allow filtering by access method. (MSAPP-2200)
  • The "External Logins" page now has a map. (MSAPP-2081)
  • The Network Monitoring page now correctly displays the Host Monitoring page when you click on a host. (MSAPP-1376, MSAPP-1920)

Current known issues

The Splunk App for Microsoft Exchange has the following known issues:

  • The dashboard builder does not work properly with Internet Explorer version 8 or earlier. To work around the problem, use another Splunk Enterprise-supported browser. (MSAPP-2259, MSAPP-2277)
  • If you click the Back button on your browser when you are in the Setup page for the app, the app incorrectly reloads the Setup page instead of returning you to the page you were on before you loaded the Setup page. This problem appears to only happen with Internet Explorer 11. (MSAPP-2245)
  • If you upgrade Splunk after installing the Splunk App for Microsoft Exchange, you might experience spurious JavaScript errors when you next load the app. To fix the problem, perform a hard refresh of the page (usually by clicking your web browser's 'Reload' icon while holding down the Shift key. (MSAPP-2162)
  • Some minor artifacts occur when you collapse the "Add Panels" sidebar on the Dashboard Builder page. (MSAPP-2109)
  • Some minor artifacts occur when navigating through the app menus. (MSAPP-2061)

Change log (what's been fixed)

  • The app now properly computes Exchange Server 2013 server roles. (MSAPP-2938)
  • The "Top Mailboxes" and "Folders by size" dashboards now allow filtering by hostname as well as database. (MSAPP-2778)
  • Several issues with the License Manager input have been fixed. (MSAPP-2759)
  • The TA-DomainController-2012R2 add-on now properly returns Active Directory forest and schema information on child domains on Windows Server 2012 R2. (MSAPP-2627, MSAPP-2756)
  • The "Messaging Activity Overview" page no longer truncates results when displaying large amounts of data. (MSAPP-MSAPP-2509, MSAPP-2630)
  • Host drop down boxes now properly sort hosts alphabetically and are no longer case sensitive. (MSAPP-2548)
  • Throttling counters for TA-Exchange2013-ClientAccess add-on have been changed. (MSAPP-2482)
  • The app now indexes MSExchange:X:Database-Stats events properly. (MSAPP-2472)
  • The mailbox audit log scripts included with the Exchange add-ons are more efficient. (MSAPP-2401)
  • The Exchange Overview page now uses more efficient searches. (MSAPP-2386)
  • The app now works properly in a master/slave license environment. (MSAPP-2250)
  • Column sorting does not work properly on the Network Monitor browser page. (MSAPP-1815, SPL-80746)
  • A cosmetic issue with the Tools and Settings menu item has been fixed. (MSAPP-2950)
  • A cosmetic issue with the Organizational Units report has been fixed. (MSAPP-2363)
Last modified on 04 September, 2014
PREVIOUS
Best practices guide
  NEXT
Third-party software attributions/credits

This documentation applies to the following versions of Splunk® App for Microsoft Exchange (EOL): 3.0.2


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters