Content Pack for Microsoft Exchange

Content Pack for Microsoft Exchange

This documentation does not apply to the most recent version of Content Pack for Microsoft Exchange. For documentation on the most recent version, go to the latest release.

Migrate from the Splunk App for Microsoft Exchange to the Content Pack for Microsoft Exchange

The Content Pack for Microsoft Exchange replicates the dashboards and reports available in the Splunk App for Microsoft Exchange. Users of ITSI version 4.9.0 or higher, or IT Essentials Work version 4.9.0 or higher can migrate from the legacy app to the content pack to take advantage of a consolidated experience. In addition, migrating means you can upgrade all content packs by upgrading the one app, the Splunk App for Content Packs.

Refer to the following table to compare the features of the app versus the content pack:

Feature Splunk App for Microsoft Exchange Splunk Content Pack for Microsoft Exchange
Installation and Configuration Manual Automatic with Splunk App for Content Packs
Built-in Microsoft Best Practices No Yes
Dashboards 48 48
Glass Tables 0 3
KPIs 22 440
Services 11 64


On October 22 2021, the Splunk App for Microsoft Exchange will reach its end of life. After this date, Splunk will no longer maintain or develop this product. The functionality in this app is migrating to the Content Pack for Microsoft Exchange.

If you are currently using the Splunk App for Microsoft Exchange your deployment might look like the following image:

This image is a diagram of a pre-migration to the content pack deployment. A series of connected boxes represent different parts of a deployment and include the Exchange Forwarders, Indexers, and Search Heads. Review the table that follows for more info.
Exchange forwarder Indexer Search head
Splunk Add-on for Microsoft Exchange
Splunk Add-on for Windows
Splunk App for Microsoft Exchange
Splunk Supporting Add-on for Active Directory

You can review the dashboards included in the Content Pack for Microsoft Exchange before you migrate. See, Dashboard reference for the Content Pack for Microsoft Exchange.

Migration options

You have two options for migrating to the Content Pack for Microsoft Exchange:

  1. One option is to disable the Splunk App for Microsoft Exchange to use the same environment. This migration option is fastest but results in an interruption of user access to your associated dashboards and knowledge objects.
  2. Your second option is to configure the Content Pack for Microsoft Exchange in a new environment. Choose this option to avoid an interruption of user access to your associated dashboards and knowledge objects.

If you choose the option of using the same environment, you must disable the Splunk App for Microsoft Exchange before installing the Content Pack for Microsoft Exchange. Both the app and content pack use the same knowledge objects, with the same definitions, and cannot be on the same search head.

Disable the Splunk App for Microsoft Exchange to use the same environment

The first option for migrating from the Splunk App for Microsoft Exchange to the Content Pack for Microsoft Exchange is to disable the Splunk App for Microsoft Exchange to use the same environment. Failure to first disable the Splunk App for Microsoft Exchange can cause knowledge object conflicts.


Disable the legacy app and install the Splunk App for Content Packs

Follow these steps to use your existing Splunk App for Microsoft Exchange environment search heads to install the Content Pack for Microsoft Exchange:

  1. On all search heads where the Splunk App for Microsoft Exchange is located, go to Apps > Manage Apps.
  2. Locate the Splunk App for Microsoft Exchange and select Disable. After disabling the app, associated dashboards and knowledge objects won't be accessible, and the knowledge objects won't run or perform any action.
  3. Install IT Service Intelligence (ITSI) or IT Essentials Work on the same search head with Exchange data according to your type of deployment. Refer to these topics in the Splunk IT Service Intelligence Install and Upgrade Manual:
    1. Install Splunk IT Service Intelligence on a single instance.
    2. Install Splunk IT Service intelligence in a distributed environment.
    3. Install IT Service Intelligence in a search head cluster environment.
    4. Install IT Essentials Work.
  4. Install the Splunk App for Content Packs according to your type of deployment:
    1. Install the Splunk App for Content Packs on a single, on-premises environment.
    2. Install the Splunk App for Content Packs on a search head cluster environment.
    3. Install the Splunk App for Content Packs on a distributed environment.

After following the previous steps, the deployment looks like the following image:

This image is a diagram of a post-migration to the content pack deployment. A series of connected boxes represent different parts of a deployment and include the Exchange Forwarders, Indexers, and Search Heads. Review the table that follows for more info.
Exchange forwarder Indexer Search head
Splunk Add-on for Microsoft Exchange
Splunk Add-on for Windows
Splunk App for Microsoft Exchange Disabled
ITSI or IT Essentials Work
Splunk App for Content Packs

Install and configure the content pack

You can now install the content pack and make configurations:

  1. Make sure that the Exchange data collected using Splunk Add-on for Microsoft Exchange is searchable from the search head where you installed the Splunk App for Content Packs.
  2. Install and configure the Content Pack for Microsoft Exchange.

Access the dashboards in the content pack

You can now access the dashboards from the content pack:

  1. In Splunk Web, open ITSI or IT Essentials Work.
  2. From the main navigation bar choose Dashboards > Dashboards.
  3. From the list of dashboards, those with the suffix - Microsoft Exchange are from the Content Pack for Microsoft Exchange. Select the dashboard title to open the dashboard.

Configure the Content Pack for Microsoft Exchange in a new environment

The second option for migrating from the Splunk App for Microsoft Exchange to the Content Pack for Microsoft Exchange is to configure the content pack in a new environment.

To configure the content pack in a new environment, create a test environment and perform these steps to set up the Content Pack for Microsoft Exchange:

  1. After installing the Splunk App for Content Packs, install the content pack in your test environment.
  2. Once you complete testing the content pack in your test environment, install the content pack in your production environment.

To learn how to install the content pack, see Install and configure the Content Pack for Microsoft Exchange.

Last modified on 29 November, 2022
Install and configure the Content Pack for Microsoft Exchange   Use the Content Pack for Microsoft Exchange

This documentation applies to the following versions of Content Pack for Microsoft Exchange: 1.4.3, 1.5.0


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters