Splunk® App for Microsoft Exchange (EOL)

Deploy and Use the Splunk App for Microsoft Exchange

On October 22 2021, the Splunk App for Microsoft Exchange will reach its end of life. After this date, Splunk will no longer maintain or develop this product. The functionality in this app is migrating to a content pack in Data Integrations. Learn about the Content Pack for Microsoft Exchange.
This documentation does not apply to the most recent version of Splunk® App for Microsoft Exchange (EOL). For documentation on the most recent version, go to the latest release.

Release notes

This topic contains information on new features, known issues, and updates as we version the Splunk App and Technology Add-ons for Microsoft Exchange.

What's new

Here's what's new in the latest version of the Splunk App for Microsoft Exchange:

  • Improved app setup.
  • Improved application component deployment. Forwarder Access Components (FACs, fwd_* apps) are now technology add-ons (TAs). They are easier to configure and deploy, particularly with deployment servers.
  • Improved message-tracking scheme, including support for non-Exchange servers in the mail routing structure.
  • Added support for Blackberry Enterprise Server (BES) v5.0.3.
  • Added information about Exchange server log transactions.
  • Administrative audit logging (available only in Exchange 2010 environments).
  • Visibility into ActiveSync data wipe requests on remote devices (available only in Exchange 2010 environments).
  • Additional improved knowledge layers.
  • Numerous bug fixes.

Current known issues

The Splunk App for Microsoft Exchange has the following known issues:

  • The "Drive Free Space" collection does not count disk space usage on mount points against the active mailbox database size view. (LABS-685)
  • The login statistics for Post Office Protocol version 3 (POP3) and Internet Message Access Protocol version 4 revision 1 (IMAP4) do not include the IP address for each login. (LABS-281)
  • In Exchange 2010 environments with Service Pack 2 (SP2) installed, the app UI does not properly display some user and server information. Additionally, Exchange servers in those environments log "Cannot load Windows Powershell snap-in" to splunkd.log because of missing PowerShell extensions. Review "Issues with Splunk App for Microsoft Exchange and MS Exchange 2010 SP2" for additional information and a workaround. (MSEXCH-242)
  • Older versions of the universal forwarder might not correctly get some Windows events. To fix this issue, upgrade your forwarders to the latest version. (SPL-51312)

Change log (what's been fixed)

The Splunk App for Microsoft Exchange version 1.1 has over 100 bugfixes over version 1.0. A list of these bugfixes will be listed here shortly.

Last modified on 27 June, 2012
Troubleshoot the Splunk App for Microsoft Exchange  

This documentation applies to the following versions of Splunk® App for Microsoft Exchange (EOL): 1.1, 1.1.1, 1.1.4, 1.1.5, 1.1.6


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters