This topic details the list of permissions you must have in order to install the Splunk App for Microsoft Exchange.
Administrative access to Exchange servers
In order to install the Splunk App for Microsoft Exchange, you must have administrative access to Exchange server and be able to make configuration changes.
Administrative access to Active Directory
In order to make changes to Active Directory services, such as enabling debug logging in DNS and increasing Active Directory audit policy, you must be a domain administrator in the Active Directory domain(s) you want to monitor.
Administrative access to Windows servers
You must have administrative access to all Windows servers - and especially Exchange servers - in the Splunk App for Microsoft Exchange deployment. The central servers require this access to install Splunk Enterprise. Any servers in the field also require this access to install universal forwarders. Splunk must run as a user with administrative access to the machine.
Platform and hardware requirements
What data the Splunk App for Microsoft Exchange collects
This documentation applies to the following versions of Splunk® App for Microsoft Exchange (Legacy): 3.4.2, 3.4.3, 3.4.4, 3.5.0, 3.5.1, 3.5.2, 4.0.0, 4.0.1