Splunk® App for Microsoft Exchange (EOL)

Deploy and Use the Splunk App for Microsoft Exchange

On October 22 2021, the Splunk App for Microsoft Exchange will reach its end of life. After this date, Splunk will no longer maintain or develop this product. The functionality in this app is migrating to a content pack in Data Integrations. Learn about the Content Pack for Microsoft Exchange.
This documentation does not apply to the most recent version of Splunk® App for Microsoft Exchange (EOL). For documentation on the most recent version, go to the latest release.

What data the Splunk App for Microsoft Exchange collects

The Splunk Add-ons for Microsoft Exchange, Microsoft Active Directory, and Windows DNS collect data from your Windows, Active Directory, and Exchange servers. They then send the data to an indexer, which the app uses in its dashboards, charts, and reports. This topic discusses the specifics of the data that the app collects and displays.

The Splunk Add-ons for Microsoft Exchange collects the following data using file inputs:

  • Internet Information Server (IIS) logs for the Exchange servers whose designated roles require IIS
  • Performance monitoring data.
  • Active Directory logs (via the Splunk Add-ons for Windows, Microsoft Active Directory, and Windows DNS)
  • Windows network, host, and printer monitoring information (via the Splunk Add-on for Windows.)
  • Windows Event logs (via the Splunk Add-on for Windows):
    • Security Logs
    • Exchange audit logs
    • Application logs, such as Forefront Protection Services (FPS) security logs

The Splunk Add-ons for Microsoft Exchange collects the following data using scripted inputs:

  • Senderbase/reputation data. This feature needs internet access to function, as it looks up the reputation score for your email users.
  • Topology and Health information
  • Mailbox Server health and usage information

If you're using TA-Windows version 6.0.0 or later, you don't need TA_AD and TA_DNS. TA_AD and TA_DNS are merged with TA-Windows version 6.0.0.

Where the Splunk App for Microsoft Exchange sends its data

The Splunk App for Microsoft Exchange puts the data it indexes into several indexes:

  • The Exchange, IIS, and application logs get indexed into the msexchange index.
  • The performance monitor logs get indexed into the perfmon index.

These indexes must be present on the indexer.

Last modified on 18 October, 2019
Permissions checklist   What a Splunk App for Microsoft Exchange deployment looks like

This documentation applies to the following versions of Splunk® App for Microsoft Exchange (EOL): 4.0.0, 4.0.1, 4.0.2, 4.0.3


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters