Install a universal forwarder on each Exchange server
Splunk forwarders are configured to send data to a central Splunk instance, which then indexes the data for use in searches and analysis. Before you can use the Splunk App for Microsoft Exchange, you must install a universal forwarder on each of the Microsoft Exchange servers you want to include in your Splunk App for Exchange deployment.
Start with the information in "Universal forwarder deployment overview" in the core Splunk documentation and then pick the relevant topic later in the same chapter for the specific instructions you need based on your environment.
Once you've installed the universal forwarders, you can proceed to deploying the relevant Splunk App for Microsoft Exchange components to each one.
Caution: Do not install a full Splunk instance on an Exchange server. Both full Splunk and Exchange have resource requirements that preclude installation of both services on one computer.
How to deploy the Splunk App for Microsoft Exchange | Make configuration changes to match your existing environment |
This documentation applies to the following versions of Splunk® App for Microsoft Exchange (EOL): 1.1, 1.1.1, 1.1.4, 1.1.5, 1.1.6
Feedback submitted, thanks!