Splunk® App for Microsoft Exchange (EOL)

Deploy and Use the Splunk App for Microsoft Exchange

On October 22 2021, the Splunk App for Microsoft Exchange will reach its end of life. After this date, Splunk will no longer maintain or develop this product. The functionality in this app is migrating to a content pack in Data Integrations. Learn about the Content Pack for Microsoft Exchange.
This documentation does not apply to the most recent version of Splunk® App for Microsoft Exchange (EOL). For documentation on the most recent version, go to the latest release.

Download and configure the Splunk Add-on for Microsoft Active Directory

The Splunk Add-on for Microsoft Active Directory is available on Splunkbase. When you download and deploy the add-ons to domain controllers, the add-ons collect Active Directory data and send it to Splunk App for Microsoft Exchange indexers.

Note: If you are using TA-Windows version 6.0.0 or later then you don't need TA_AD and TA_DNS, as they are merged with TA-Windows. To configure TA-Windows v6.0.0, Please refer to Deploy and configure the Splunk Add-on for Windows version 6.0.0 or later.

More information about the Active Directory add-ons

The following table lists details about the Active Directory add-on.

Add-on Description
Splunk_TA_microsoft_ad For Active Directory domain controllers that run Windows Server 2008, 2008 R2, 2012 R2 and later.

Download the Splunk Add-on for Microsoft Active Directory

The Splunk Add-on for Microsoft Active Directory are available on Splunkbase.

  1. In a web browser, proceed to the Splunk Add-on for Microsoft Active Directory download page.
  2. Click the download link to begin the download process. You might need to sign in with your Splunk account before the download starts.
  3. When prompted, choose an accessible location on your deployment server to save the download. Do not attempt to run the download.
  4. Use an archive utility such as WinZip to unarchive the file to an accessible location.

Configure the Splunk Add-on for Microsoft Active Directory

The Splunk Add-on for Microsoft Active Directory do not require any configuration edits by default. When you deploy them onto Active Directory domain controllers, they immediately begin collecting data as long as you have configured audit policy.

Next Step

You have downloaded the Splunk Add-on for Microsoft Active Directory.

Deploy the Splunk Add-ons for Active Directory

Last modified on 18 October, 2019
Configure PowerShell Execution policy in Active Directory   Deploy the Splunk Add-on for Microsoft Active Directory

This documentation applies to the following versions of Splunk® App for Microsoft Exchange (EOL): 4.0.0, 4.0.1, 4.0.2, 4.0.3


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters