Splunk® App for Microsoft Exchange

Deploy and Use the Splunk App for Microsoft Exchange

Acrobat logo Download manual as PDF


This documentation does not apply to the most recent version of MSExchange. Click here for the latest version.
Acrobat logo Download topic as PDF

Release notes

This topic contains information on new features, known issues, and updates as we version the Splunk App and Add-ons for Microsoft Exchange.

What's new

  • Django is no longer supported. Dashboards and panels built using the Django framework will not work in versions 3.4.0 and later of the Splunk App for Microsoft Exchange. All customer created dashboards built using the custom dashboard builder will no longer be available for use in versions 3.4.0 and above.

All dashboards shipped as part of the exchange app will still be available by navigating to Core Views > Dashboards.

Exchange dashboard navigation sample.png

  • SSO is now supported. Previously, Django URL rendering conflicted with SSO URL formats.

Current known issues

The Splunk App for Microsoft Exchange has the following known issues:

Report Date Issue Number Description
2016-12-30 EXC-2052 read-audit-logs_2010_2013.ps1 failure. The search command search-adminauditlog used in read-audit-logs_2010_2013, does not work in PowerShell for the 2016 Exchange Server product. The MSExchange:2013:AdminAudit sourcetype will not display in Splunk platform searches.

Fixed issues

Fixed issues

Publication date Defect number Description
2016-08-29 EXC-2005 AppInspect change : deprecated properties are used in xml
2016-11-21 EXC-2035 Update the sa-microsoft to integrate the feature like "Customize features only option" and "Features are detected one after the other"
2016-11-21 EXC-2027 Exchange app dropdown menu freezes
2016-11-18 EXC-2026 Splunk Exchange App - Slow Search Results
2016-11-12 EXC-2018 MSExchange:2010:AdminAudit - SearchQuery within CmdletParam field is not correctly extracted
2016-11-09 EXC-756 TA-Exchange-2010-HubTransport is not fully CIM compliant
2016-11-08 EXC-1973 MS Exchange app is creating data model summary artifacts in the _internal and _introspection indexes
Last modified on 06 February, 2017
PREVIOUS
Best practices guide
  NEXT
Third-party software attributions/credits

This documentation applies to the following versions of Splunk® App for Microsoft Exchange: 3.4.1


Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters