Splunk® App for Microsoft Exchange (EOL)

Deploy and Use the Splunk App for Microsoft Exchange

On October 22 2021, the Splunk App for Microsoft Exchange will reach its end of life. After this date, Splunk will no longer maintain or develop this product. The functionality in this app is migrating to a content pack in Data Integrations. Learn about the Content Pack for Microsoft Exchange.

Deploy the Splunk Add-on for Windows

After you deploy the Splunk Add-on for Windows to the deployment clients that you have configured to connect to the deployment server, the deployment clients begin collecting Windows data and sending it to the indexer.

Place the add-on in the deployment apps directory on the deployment server

The deployment server must be made aware of the Splunk Add-on for Windows.

  1. Open a command prompt on the deployment server/indexer.
  2. Copy the entire Splunk Add-on for Windows folder from its current location to the deployment apps directory.
    > Copy-Item -Path C:\Downloads\Splunk_TA_Windows -Destination "C:\Program Files\Splunk\etc\deployment-apps\Splunk_TA_Windows" -Recurse
  3. Tell the deployment server to reload its deployment configuration.
    > cd \Program Files\Splunk\bin
    > .\splunk reload deploy-server
  4. From a web browser, log into Splunk Enterprise on the deployment server.
  5. In the system bar, select Settings > Forwarder Management.
  6. Click the Apps tab. You should see the Splunk_TA_Windows add-on in the list of apps.
    Exch 31 DeployApps TAWindows.png
  7. In the "Splunk_TA_Windows" add-on entry in the list, click Edit. The "Edit App: Splunk_TA_Windows" page loads.
  8. Click "+" under "Server Classes".
  9. Select the "Universal Forwarders" server class that you created during the initial setup phase. Splunk Enterprise displays the deployment clients that will receive the add-on in the lower half of the page.
  10. Confirm that the deployment client that you set up previously appears in the list.
  11. Click Save. Splunk Enterprise saves the configuration, the Forwarder Management menu reappears, and the deployment server deploys the Splunk_TA_Windows add-on to the deployment client.

Next Step

You have deployed the Splunk Add-on for Windows onto your deployment client. In the future, you can use this procedure to deploy the add-on to additional clients.

Confirm and troubleshoot Windows data collection

Last modified on 06 October, 2021
Download and configure the Splunk Add-on for Windows   Confirm and troubleshoot Windows data collection

This documentation applies to the following versions of Splunk® App for Microsoft Exchange (EOL): 4.0.4

Was this topic useful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters