Splunk® App for Microsoft Exchange (EOL)

Splunk App for Microsoft Exchange Reference

Acrobat logo Download manual as PDF

On October 22 2021, the Splunk App for Microsoft Exchange will reach its end of life. After this date, Splunk will no longer maintain or develop this product. The functionality in this app is migrating to a content pack in Data Integrations. Learn about the Content Pack for Microsoft Exchange.
This documentation does not apply to the most recent version of MSExchange. Click here for the latest version.
Acrobat logo Download topic as PDF

Failed Logons

Exch 30 adfailedlogons.png

The Failed Logons dashboard provides insight into recent failed attempts by users to log into your domain. Specific statistics include:

  • Failed logons over time.
  • Failed interactive logons by IP address.
  • Failed logons by reason (for example, expired password, locked account, or disabled account.)
  • Failed interactive logons by username.
  • Failed logons by logon type.
  • Users failing to logon from multiple IPs (for example, an active attempt to break into the network.)

This dashboard's selection panel allows you to filter results based on Forest, Site, Domain, and Server. You can also control how much information the app displays by selecting the time range you desire in the time range picker on the upper right side of the dashboard.

Last modified on 04 April, 2017
User Record Changes
AD Anomalous Logons

This documentation applies to the following versions of Splunk® App for Microsoft Exchange (EOL): 3.4.2, 3.4.3, 3.4.4, 3.5.0, 3.5.1, 3.5.2, 4.0.0, 4.0.1, 4.0.2, 4.0.3

Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters