Splunk® App for Microsoft Exchange (EOL)

Splunk App for Microsoft Exchange Reference

On October 22 2021, the Splunk App for Microsoft Exchange will reach its end of life. After this date, Splunk will no longer maintain or develop this product. The functionality in this app is migrating to a content pack in Data Integrations. Learn about the Content Pack for Microsoft Exchange.
This documentation does not apply to the most recent version of Splunk® App for Microsoft Exchange (EOL). For documentation on the most recent version, go to the latest release.

Top Users and Folders

Exch 302 topmailboxesandfolders.png

This page displays information on the top users and folders in your Exchange network.

It has panels that show the top users by total mailbox size, top users by the size of their Deleted Items folder, the top folder types by size, and the top users by the size of their Junk Email folder.

How to use this page

  • To find out more about a top user, click on that user in any of the "Top Users by Mailbox Size", "Top Users by Deleted Items Size", or "Top Users with Junk Email" lists. The Splunk App for Microsoft Exchange loads the "User Behavior Overview" page and filters results to the specified user.
  • If you click on an entry in the "Top Folder Types by Size" panel, the Splunk App for Microsoft Exchange brings up the base search that produced the selected folder size events. It also includes any events which match the selected folder, and displays a statistics page which lists the users who have items in that folder, sorted alphabetically.
Last modified on 13 January, 2017
Public Folder Usage   Unused Mailboxes

This documentation applies to the following versions of Splunk® App for Microsoft Exchange (EOL): 3.4.1


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters