TA-Exchange-HubTransport inputs
The TA-Exchange-HubTransport add-on collects performance and Windows host monitoring data from Windows hosts that run Exchange Server and hold the Hub Transport role. See Configure TA-Exchange-HubTransport to learn how to configure the add-on for your version of Exchange Server prior to deploying it to Exchange Server hosts.
The add-on includes the following data inputs:
####Common Stanzas - Start#### [WinHostMon://Processes] [WinHostMon://Services] [perfmon://Total_Processor_Time] [perfmon://Processor] [perfmon://System] [perfmon://Available_Memory] [perfmon://Memory] [perfmon://DotNET_CLR_Memory] [perfmon://Network_Utilization] [perfmon://TCPv4] [perfmon://TCPv6] [perfmon://Disk] [perfmon://MSExchange_Control_Panel] [perfmon://MSExchange_Queue_Lengths] [perfmon://MSExchange_Transport_Dumpster] [perfmon://MSExchange_Store_Driver] [perfmon://MSExchange_SmtpReceive] [perfmon://MSExchange_SmtpSend] [perfmon://MSExchange_Extensibility_Agents] ####Common Stanzas - End#### ####Exchange Server 2010 - Start#### [monitor://C:\Program Files\Microsoft\Exchange Server\V14\TransportRoles\Logs\MessageTracking] [script://.\bin\exchangepowershell.cmd v14 read-audit-logs_2010.ps1] [script://.\bin\exchangepowershell.cmd v14 get-hoststats_2007_2010.ps1] ####Exchange Server 2010 - End#### ###From Exchange app/add-on version 3.5.2,support for exchange server 2007 has ended.### ####Exchange Server 2007 - Start#### [monitor://C:\Program Files\Microsoft\Exchange Server\TransportRoles\Logs\MessageTracking] [script://.\bin\exchangepowershell.cmd v8.0 get-hoststats_2007_2010.ps1] ####Exchange Server 2007 - End####
For the admin audit log data collection, the PowerShell script saves the checkpoint (date) when this data was previously collected. Saving this checkpoint creates and uses splunk-msexchange-auditfile.clixml, which uses %TEMP% as a location and C:\Windows\Temp as a path for the NT Authority\SYSTEM account.
Overview of TA-Exchange-HubTransport | Configure TA-Exchange-HubTransport |
This documentation applies to the following versions of Splunk® App for Microsoft Exchange (EOL): 3.5.2, 4.0.0, 4.0.1, 4.0.2, 4.0.3
Feedback submitted, thanks!