Splunk® App for Microsoft Exchange (EOL)

Deploy and Use the Splunk App for Microsoft Exchange

On October 22 2021, the Splunk App for Microsoft Exchange will reach its end of life. After this date, Splunk will no longer maintain or develop this product. The functionality in this app is migrating to a content pack in Data Integrations. Learn about the Content Pack for Microsoft Exchange.
This documentation does not apply to the most recent version of Splunk® App for Microsoft Exchange (EOL). For documentation on the most recent version, go to the latest release.

Troubleshoot the Splunk App for Microsoft Exchange

This topic discusses how you can troubleshoot your Splunk App for Microsoft Exchange deployment if you aren't seeing the data that you expect.

Windows event log or performance events from universal forwarders go to the 'main' index

When you install a universal forwarder on your Exchange server, you must not select any options in the Enable Inputs screen of the installer. Doing so enables the scripted inputs that come with the forwarder by default. Those inputs send data to the "default" index as specified in their configuration files, which, on a standard Splunk installation, is main.

After you install the universal forwarder onto your exchange server, you must then install the appropriate technology add-ons included in the Splunk App for Microsoft Exchange's installation package. You must place the TAs in %SPLUNK_HOME%\etc\apps within the universal forwarder. Review "Deploy configurations for all server roles" for specific instructions.

Last modified on 04 July, 2012
Dashboard reference   Release notes

This documentation applies to the following versions of Splunk® App for Microsoft Exchange (EOL): 1.1, 1.1.1, 1.1.4, 1.1.5, 1.1.6


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters