Sample Exchange searches and dashboards
This topic lists searches that you can perform to confirm that Exchange data has arrived at the indexer.
Search Exchange data
To confirm that Exchange data is present on the indexer, use the Search app:
1. Log into Splunk Enterprise on the indexer, if you have not already.
2. Load the Search app. In the system bar, select Apps > Search & Reporting. Splunk loads the Search app.
3. Try the following searches to confirm that data is present:
This search confirms that the Splunk Add-on for Microsoft Exchange is sending data to the indexer:
sourcetype="MSExchange*"
This search confirms that the Splunk Add-on for Microsoft Exchange is sending Performance Monitoring data for Exchange':
index=msexchange sourcetype="Perfmon*"
Can't find the data?
Try the following:
- Use Forwarder Management to confirm that the Splunk Add-on for Microsoft Exchange have been deployed to your deployment clients.
- Refer to the Troubleshooting manual for additional help.
Confirm and troubleshoot Exchange data collection | Install the Splunk App for Microsoft Exchange on the search head |
This documentation applies to the following versions of Splunk® App for Microsoft Exchange (EOL): 3.4.2, 3.4.3, 3.4.4, 3.5.0, 3.5.1, 3.5.2, 4.0.0, 4.0.1, 4.0.2, 4.0.3
Feedback submitted, thanks!