Splunk® App for Microsoft Exchange (EOL)

Deploy and Use the Splunk App for Microsoft Exchange

Acrobat logo Download manual as PDF


On October 22 2021, the Splunk App for Microsoft Exchange will reach its end of life. After this date, Splunk will no longer maintain or develop this product. The functionality in this app is migrating to a content pack in Data Integrations. Learn about the Content Pack for Microsoft Exchange.
This documentation does not apply to the most recent version of Splunk® App for Microsoft Exchange (EOL). For documentation on the most recent version, go to the latest release.
Acrobat logo Download topic as PDF

How to upgrade the Splunk App for Microsoft Exchange

This topic discusses supported upgrade scenarios for the Splunk App for Microsoft Exchange.

The commands shown in this topic are PowerShell. If you use *nix, substitute the PowerShell directives with their *nix counterparts. If you use different directories for Splunk Enterprise and deployment server, substitute the directories shown with your specific directories.

Upgrade overview

There are two supported upgrade scenarios available for the Splunk App for Microsoft Exchange:

  • From version 3.0.x and earlier to this version.
  • From version 3.1.x to this version.

Upgrade tips

From version 3.0.x and earlier to this version

When you upgrade the app from version 3.0.x to version 3.1.2, note the following:

  • Disk space and memory requirements on dedicated search heads increase significantly because of app key value store, increased lookup sizes, and a data model. These requirements increase based on the number of hosts in your deployment. You might need to add more storage or replace search heads with hosts that have more memory and CPU cores available. See "Size and scale a Splunk App for Microsoft Exchange deployment."

From version 3.1.x to this version

When you upgrade the app from version 3.1.1 to this version, note that the upgrade process deletes the local settings in the app key value store. Once you complete the upgrade, you must:

  • Reconfigure any thresholds that you set up previously in the "Thresholds" dialog in Service Analyzer. See "Change thresholds".


Troubleshoot permissions issues after an upgrade

When you upgrade the Splunk App for Microsoft Exchange to version 3.1.x, the app installs a new user role, exchange-admin. The Splunk user that uses the Splunk App for Microsoft Exchange must have this role, otherwise the app will not function correctly.

If, during the first time process, you see that the app does not find any data and you know that the data exists (such as in the case of an upgrade), be sure to add the exchange-admin role to the user that uses the app, as described in the troubleshooting page.

Last modified on 07 March, 2015
PREVIOUS
Install a license
  NEXT
Upgrade from 3.0.x and earlier

This documentation applies to the following versions of Splunk® App for Microsoft Exchange (EOL): 3.1.2, 3.1.3, 3.2.0, 3.2.1


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters