Splunk® App for Microsoft Exchange (EOL)

Deploy and Use the Splunk App for Microsoft Exchange

On October 22 2021, the Splunk App for Microsoft Exchange will reach its end of life. After this date, Splunk will no longer maintain or develop this product. The functionality in this app is migrating to a content pack in Data Integrations. Learn about the Content Pack for Microsoft Exchange.
This documentation does not apply to the most recent version of Splunk® App for Microsoft Exchange (EOL). For documentation on the most recent version, go to the latest release.

How to upgrade the Splunk App for Microsoft Exchange

The commands that appear in this topic are for use on PowerShell. If you use *nix, substitute PowerShell commands with *nix counterparts. If you use different directories for Splunk Enterprise and deployment server, substitute the directories that appear here with your specific directories.

Upgrade overview

The following supported upgrade scenarios are available for the Splunk App for Microsoft Exchange:

  • From version 3.2.x to this version.

Upgrade tips

From version 3.2.x to this version

When you upgrade the Splunk App for Microsoft Exchange to the latest version, note the following:

  • The Splunk Add-ons for Microsoft Exchange, Microsoft Active Directory, and Windows DNS have changed significantly. They have new names (TA-Microsoft-Exchange*/TA-Windows-Exchange-IIS, TA-Microsoft-AD, and TA-Microsoft-DNS) and improved function. Instead of an add-on for each version of Windows or Exchange, the add-ons now support all versions of Windows and Exchange that Splunk Enterprise supports.
  • Instead of coming packaged with the Splunk App for Microsoft Exchange, all of these add-ons are now available as separate downloads on Splunkbase.
  • You must remove the existing add-ons and download and install the new add-ons.
  • The Splunk Add-ons for Microsoft Active Directory and Windows DNS must be installed on all search heads and indexers in the deployment.
  • The Splunk Add-ons for Microsoft Exchange replace the suite of individual add-ons that came with the Splunk App for Microsoft Exchange installation package. For more information about the updated Splunk Add-on for Microsoft Exchange, see Download and configure the Splunk Add-on for Microsoft Exchange.
  • For more information about the Splunk Add-ons for Microsoft Active Directory and Windows DNS, see About the Splunk Add-on for Microsoft Active Directory and About the Splunk Add-on for Windows DNS.

See Upgrade from version 3.2.x for the upgrade procedure.

Troubleshoot permissions issues after an upgrade

When you upgrade the Splunk App for Microsoft Exchange to version 3.1.x, the app installs a new user role, exchange-admin. The Splunk user that uses the Splunk App for Microsoft Exchange must have this role, otherwise the app will not function correctly.

If, during the first time process, you see that the app does not find any data and you know that the data exists (such as in the case of an upgrade), be sure to add the exchange-admin role to the user that uses the app, as described in the troubleshooting page.

Last modified on 27 July, 2016
Install a license   Upgrade from 3.0.x and earlier

This documentation applies to the following versions of Splunk® App for Microsoft Exchange (EOL): 3.3.0


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters