<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Microsoft Communicator &amp; Instant Messaging in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Microsoft-Communicator-Instant-Messaging/m-p/14753#M1538</link>
    <description>&lt;P&gt;I don't know about other IM platforms but with Office Communications Server (server component for Communicator) you need to enable Call Detail Recording. Otherwise, OCS will not record the data you're looking for. With CDR you have the option of collecting just utilization stats or archiving entire IM conversations.&lt;/P&gt;

&lt;P&gt;Then it's just a matter of writing a script to export the data from the SQL database CDR stores them in. &lt;/P&gt;</description>
    <pubDate>Thu, 12 Aug 2010 20:21:26 GMT</pubDate>
    <dc:creator>erga00</dc:creator>
    <dc:date>2010-08-12T20:21:26Z</dc:date>
    <item>
      <title>Microsoft Communicator &amp; Instant Messaging</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Microsoft-Communicator-Instant-Messaging/m-p/14751#M1536</link>
      <description>&lt;P&gt;Can I use Splunk to do forensics on Microsoft Communicator and other IM platforms&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jun 2010 03:23:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Microsoft-Communicator-Instant-Messaging/m-p/14751#M1536</guid>
      <dc:creator>rwilbert</dc:creator>
      <dc:date>2010-06-03T03:23:17Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Communicator &amp; Instant Messaging</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Microsoft-Communicator-Instant-Messaging/m-p/14752#M1537</link>
      <description>&lt;P&gt;What exactly do you mean by forensics? Do you mean index individual chat logs? &lt;/P&gt;

&lt;P&gt;You could query the chat logs stored in the underlying Communicator SQL database using a scripted input if you have sufficient admin privileges on the Communicator server. The data you would be indexing would be "non-traditional" data for Splunk since it would be fairly free form compared to typical log data, but it would index and be searchable as text output from a scripted input that queried the database.&lt;/P&gt;

&lt;P&gt;As to other IM platforms individual chat clients sometimes store chat logs as plain txt files on the local system. If you have Splunk installed locally on the system and knew the directory of the chat logs, Splunk could index them. It would again be "non-traditional" input, but text files index quite easily.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jun 2010 13:36:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Microsoft-Communicator-Instant-Messaging/m-p/14752#M1537</guid>
      <dc:creator>DrewO</dc:creator>
      <dc:date>2010-06-03T13:36:44Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Communicator &amp; Instant Messaging</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Microsoft-Communicator-Instant-Messaging/m-p/14753#M1538</link>
      <description>&lt;P&gt;I don't know about other IM platforms but with Office Communications Server (server component for Communicator) you need to enable Call Detail Recording. Otherwise, OCS will not record the data you're looking for. With CDR you have the option of collecting just utilization stats or archiving entire IM conversations.&lt;/P&gt;

&lt;P&gt;Then it's just a matter of writing a script to export the data from the SQL database CDR stores them in. &lt;/P&gt;</description>
      <pubDate>Thu, 12 Aug 2010 20:21:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Microsoft-Communicator-Instant-Messaging/m-p/14753#M1538</guid>
      <dc:creator>erga00</dc:creator>
      <dc:date>2010-08-12T20:21:26Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Communicator &amp; Instant Messaging</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Microsoft-Communicator-Instant-Messaging/m-p/755433#M119869</link>
      <description>&lt;P data-unlink="true"&gt;Yes, you can — as long as the IM platform provides access to logs or message data. For instance, with on-prem or self-hosted solutions like MirrorFly’s Enterprise Instant Messaging Software&amp;nbsp;, you can retain all chat logs within your infrastructure and forward them to Splunk through APIs or syslog. That setup makes it easier to perform forensic analysis or compliance audits compared to hosted services where data access is limited.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Nov 2025 12:58:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Microsoft-Communicator-Instant-Messaging/m-p/755433#M119869</guid>
      <dc:creator>kathrin</dc:creator>
      <dc:date>2025-11-12T12:58:52Z</dc:date>
    </item>
  </channel>
</rss>

