<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk 4.x and Exchange 2010 in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-4-x-and-Exchange-2010/m-p/102070#M21403</link>
    <description>&lt;P&gt;how to configure this app "Splunk for Microsoft Exchange"?&lt;BR /&gt;
I have already added this addons to my Splunk instance, but I did not get it configured !!!&lt;BR /&gt;
can any one to help me!!!&lt;BR /&gt;
please..&lt;/P&gt;</description>
    <pubDate>Thu, 09 Feb 2012 18:10:37 GMT</pubDate>
    <dc:creator>RIADH</dc:creator>
    <dc:date>2012-02-09T18:10:37Z</dc:date>
    <item>
      <title>Splunk 4.x and Exchange 2010</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-4-x-and-Exchange-2010/m-p/102067#M21400</link>
      <description>&lt;P&gt;I´m running Splunk 4.x here and would like to import out flat file MS Exchange eMail tracking files into splunk. BUT it seamed there is no plugin available. Only a old one for splunk 3.x and exchange 2003 can be found.&lt;/P&gt;

&lt;P&gt;Has anybody managed to import the eMail tracking files into splunk?&lt;/P&gt;</description>
      <pubDate>Sat, 14 May 2011 05:42:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-4-x-and-Exchange-2010/m-p/102067#M21400</guid>
      <dc:creator>BastianW</dc:creator>
      <dc:date>2011-05-14T05:42:49Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk 4.x and Exchange 2010</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-4-x-and-Exchange-2010/m-p/102068#M21401</link>
      <description>&lt;P&gt;Exchange 2010 message tracking logs are simply CSV files, and don't require any special plugins for importing into Splunk. I think that the normal "exchange" sourcetype will probably generate a correct CSV field list from the file headers, but if it doesn't, one can be made by just defining the sourcetype:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[exchange2010msgtracking]
DELIMS = ","
FIELDS = date_time,client_ip,client_hostname,server_ip,server_hostname,
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;And so on...I didn't list out all the fields, but they're listed in the file header anyway.&lt;/P&gt;</description>
      <pubDate>Sat, 14 May 2011 16:51:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-4-x-and-Exchange-2010/m-p/102068#M21401</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2011-05-14T16:51:01Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk 4.x and Exchange 2010</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-4-x-and-Exchange-2010/m-p/102069#M21402</link>
      <description>&lt;P&gt;As of today, there is a new app: &lt;A href="http://splunk-base.splunk.com/apps/28976/splunk-app-for-microsoft-exchange"&gt;Splunk App for Microsoft Exchange&lt;/A&gt;.  This supports import of the Microsoft Exchange 2010 Message Tracking logs&lt;/P&gt;</description>
      <pubDate>Mon, 15 Aug 2011 18:00:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-4-x-and-Exchange-2010/m-p/102069#M21402</guid>
      <dc:creator>ahall_splunk</dc:creator>
      <dc:date>2011-08-15T18:00:19Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk 4.x and Exchange 2010</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-4-x-and-Exchange-2010/m-p/102070#M21403</link>
      <description>&lt;P&gt;how to configure this app "Splunk for Microsoft Exchange"?&lt;BR /&gt;
I have already added this addons to my Splunk instance, but I did not get it configured !!!&lt;BR /&gt;
can any one to help me!!!&lt;BR /&gt;
please..&lt;/P&gt;</description>
      <pubDate>Thu, 09 Feb 2012 18:10:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-4-x-and-Exchange-2010/m-p/102070#M21403</guid>
      <dc:creator>RIADH</dc:creator>
      <dc:date>2012-02-09T18:10:37Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk 4.x and Exchange 2010</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-4-x-and-Exchange-2010/m-p/102071#M21404</link>
      <description>&lt;P&gt;Check out the documentation on docs.splunk.com - this goes step by step on how to configure the app.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Feb 2012 18:12:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-4-x-and-Exchange-2010/m-p/102071#M21404</guid>
      <dc:creator>ahall_splunk</dc:creator>
      <dc:date>2012-02-09T18:12:42Z</dc:date>
    </item>
  </channel>
</rss>

