Troubleshoot the Splunk App for Microsoft Exchange
This topic discusses how you can troubleshoot your Splunk App for Microsoft Exchange deployment if you aren't seeing the data that you expect.
Windows event log or performance events from universal forwarders go to the 'main' index
When you install a universal forwarder on your Exchange server, you must not select any options in the Enable Inputs screen of the installer. Doing so enables the scripted inputs that come with the forwarder by default. Those inputs send data to the "default" index as specified in their configuration files, which, on a standard Splunk installation, is main
.
After you install the universal forwarder onto your exchange server, you must then install the appropriate technology add-ons included in the Splunk App for Microsoft Exchange's installation package. You must place the TAs in %SPLUNK_HOME%\etc\apps
within the universal forwarder. Review "Deploy configurations for all server roles" for specific instructions.
Dashboard reference | Release notes |
This documentation applies to the following versions of Splunk® App for Microsoft Exchange (EOL): 1.1, 1.1.1, 1.1.4, 1.1.5, 1.1.6
Feedback submitted, thanks!