<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Exchange admin audit logs in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Exchange-admin-audit-logs/m-p/96892#M20212</link>
    <description>&lt;P&gt;Yes.  Download the &lt;A href="http://splunk-base.splunk.com/apps/28976/splunk-app-for-microsoft-exchange"&gt;Splunk App for Microsoft Exchange&lt;/A&gt; - the TA-Exchange-2010-* technology add-ons that are included read the Admin Audit Logs from each server.&lt;/P&gt;</description>
    <pubDate>Thu, 12 Jul 2012 15:54:03 GMT</pubDate>
    <dc:creator>ahall_splunk</dc:creator>
    <dc:date>2012-07-12T15:54:03Z</dc:date>
    <item>
      <title>Exchange admin audit logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Exchange-admin-audit-logs/m-p/96891#M20211</link>
      <description>&lt;P&gt;Can splunk read exchange 2010 sp1 admin audit logs. I beleive  exchange admin logs goes to a configured email. Does splunk exchange app reads the exchange admin logs&lt;BR /&gt;
Thank you in advance&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jul 2012 15:50:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Exchange-admin-audit-logs/m-p/96891#M20211</guid>
      <dc:creator>nuwan</dc:creator>
      <dc:date>2012-07-12T15:50:50Z</dc:date>
    </item>
    <item>
      <title>Re: Exchange admin audit logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Exchange-admin-audit-logs/m-p/96892#M20212</link>
      <description>&lt;P&gt;Yes.  Download the &lt;A href="http://splunk-base.splunk.com/apps/28976/splunk-app-for-microsoft-exchange"&gt;Splunk App for Microsoft Exchange&lt;/A&gt; - the TA-Exchange-2010-* technology add-ons that are included read the Admin Audit Logs from each server.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jul 2012 15:54:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Exchange-admin-audit-logs/m-p/96892#M20212</guid>
      <dc:creator>ahall_splunk</dc:creator>
      <dc:date>2012-07-12T15:54:03Z</dc:date>
    </item>
    <item>
      <title>Re: Exchange admin audit logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Exchange-admin-audit-logs/m-p/96893#M20213</link>
      <description>&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jul 2012 01:24:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Exchange-admin-audit-logs/m-p/96893#M20213</guid>
      <dc:creator>nuwan</dc:creator>
      <dc:date>2012-07-13T01:24:43Z</dc:date>
    </item>
    <item>
      <title>Re: Exchange admin audit logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Exchange-admin-audit-logs/m-p/96894#M20214</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I am curious when below bug will be fixed. It is related to Exchange 2016 admin audit log extraction.&lt;/P&gt;

&lt;P&gt;2016-12-30  EXC-2052    &lt;/P&gt;

&lt;P&gt;read-audit-logs_2010_2013.ps1 failure. The search command search-adminauditlog used in read-audit-logs_2010_2013, does not work in PowerShell for the 2016 Exchange Server product. The MSExchange:2013:AdminAudit sourcetype will not display in Splunk platform searches.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 13:31:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Exchange-admin-audit-logs/m-p/96894#M20214</guid>
      <dc:creator>tomasmoser</dc:creator>
      <dc:date>2020-09-29T13:31:57Z</dc:date>
    </item>
    <item>
      <title>Re: Exchange admin audit logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Exchange-admin-audit-logs/m-p/96895#M20215</link>
      <description>&lt;P&gt;I am also curious as it seems this issue isnt getting fixed. The short answer my Splunk team got from their Splunk rep was that the account that is forwarding to the Exchange app indexes needs to be in the same domain with organizational management role in Exchange XD. Im sorry but the expectation that an Exchange team using this app would give full open ended access to a service account just to forward admin audit logs is insane.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Oct 2018 21:08:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Exchange-admin-audit-logs/m-p/96895#M20215</guid>
      <dc:creator>micnuw2</dc:creator>
      <dc:date>2018-10-17T21:08:32Z</dc:date>
    </item>
  </channel>
</rss>

