Splunk® App for Microsoft Exchange (EOL)

Deploy and Use the Splunk App for Microsoft Exchange

On October 22 2021, the Splunk App for Microsoft Exchange will reach its end of life. After this date, Splunk will no longer maintain or develop this product. The functionality in this app is migrating to a content pack in Data Integrations. Learn about the Content Pack for Microsoft Exchange.
This documentation does not apply to the most recent version of Splunk® App for Microsoft Exchange (EOL). For documentation on the most recent version, go to the latest release.

Platform and hardware requirements

This topic discusses the underlying requirements for running the Splunk App for Microsoft Exchange in production.

Hardware and Operating System requirements

A Splunk App for Microsoft Exchange deployment includes multiple components (described in more detail in "What a Splunk App for Microsoft Exchange deployment looks like" in this manual). These components can run on different platforms, so be sure you're downloading the correct platform and architecture (32- or 64-bit).

The deployment is generally divided into two separate areas: The central Splunk instance and the other instances of Splunk that send data to this instance.

  • For details about supported OSes for Splunk, refer to "System requirements" in the core Splunk product documentation.

Caution: Do not install a full instance of Splunk on a server performing any Exchange server role. Both Splunk and Exchange have individual system requirements that preclude sharing services on the same computer.

The "central Splunk instance"

The Splunk instance that runs the Splunk App for Microsoft Exchange and indexes the data is known as the "central Splunk instance," and can run on any OS that is currently supported by Splunk.

The hardware requirements for your central Splunk instance depend highly on the volume of data coming from the Exchange server(s) you are monitoring. Your Splunk Sales Engineer can help you estimate how much hardware and license capacity you will need.

  • For guidance on scaling your deployment, check out "Capacity planning" in the core Splunk product documentation.

The other Splunk instances

The other Splunk instances collect data from the various Exchange servers and forward it to the central Splunk instance. Since they are not indexing any data, this means that the hardware requirements for these components are less stringent than for the central Splunk instance.

Make sure you download the correct platform and architecture (32- or 64-bit) of Splunk for your hardware.

What versions of Microsoft Exchange are supported?

  • Exchange 2007 (requires Windows Server 2003 SP1 or 2003 R2 RTM or later)
  • Exchange 2010 SP1 and earlier (requires Windows Server 2008 SP2 or 2008 R2 SP1 or later)

Caveats

The Splunk App for Microsoft Exchange requires PowerShell management extension support, which is not included with Microsoft Exchange 2010 Service Pack 2 (SP2). Review Issues with Splunk App for Microsoft Exchange and MS Exchange 2010 SP2 for additional information."

Exchange 2003 is not supported because it does not have the level of logging capabilities that Exchange 2007 and 2010 do. The logging format for Exchange 2003 is also different from later versions of the product.

Exchange 2000 is also not supported.

What versions of Splunk are supported?

All instances of Splunk in a Splunk for Microsoft Exchange deployment must run version 4.2.5 or later.

Additional requirements

The Splunk App for Microsoft Exchange v1.1 requires the following additional components:

Last modified on 21 June, 2012
How to get support and find more information about Splunk   What data the Splunk App for Microsoft Exchange collects

This documentation applies to the following versions of Splunk® App for Microsoft Exchange (EOL): 1.1, 1.1.1, 1.1.4, 1.1.5, 1.1.6


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters