TA-Exchange-ClientAccess inputs

The TA-Exchange-ClientAccess add-on collects performance and Windows host monitoring data from Windows hosts that run Exchange Server and hold the Client Access Server role. See Configure TA-Exchange-ClientAccess to learn how to configure the add-on for your version of Exchange Server prior to deploying it to Exchange Server hosts.

The add-on includes the following data inputs:

Common data inputs


Exchange Server 2010 data inputs

[monitor://C:\Program Files\Microsoft\Exchange Server\V14\Logging\RPC Client Access]
[script://.\bin\exchangepowershell.cmd v14 get-hoststats_2007_2010.ps1]
[script://.\bin\exchangepowershell.cmd v14 get-throttling-policies_2010_2013.ps1]
[script://.\bin\exchangepowershell.cmd v14 read-audit-logs_2010_2013.ps1]

Exchange Server 2013, 2016, and 2019 data inputs

[monitor://C:\Program Files\Microsoft\Exchange Server\V15\Logging\RPC Client Access]
[script://.\bin\exchangepowershell.cmd v15 get-hoststats_2013.ps1]
[script://.\bin\exchangepowershell.cmd v15 read-audit-logs_2010_2013.ps1]
[script://.\bin\exchangepowershell.cmd v15 get-throttling-policies_2010_2013.ps1]

For the admin audit log data collection, the PowerShell script saves the checkpoint (date) when this data was previously collected. Saving this checkpoint creates and uses splunk-msexchange-auditfile.clixml, which uses %TEMP% as a location and C:\Windows\Temp as a path for the NT Authority\SYSTEM account.

