<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk for Exchange - Database information not  showing in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-for-Exchange-Database-information-not-showing/m-p/103011#M21641</link>
    <description>&lt;P&gt;Thanks for all the help.&lt;/P&gt;</description>
    <pubDate>Mon, 29 Oct 2012 16:38:43 GMT</pubDate>
    <dc:creator>deepcovelabs</dc:creator>
    <dc:date>2012-10-29T16:38:43Z</dc:date>
    <item>
      <title>Splunk for Exchange - Database information not  showing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-for-Exchange-Database-information-not-showing/m-p/102997#M21627</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;We are int he process of setting up Splunk for Exchange App and we seem to has it running, somewhat correctly, but the app does not display the mailstore db size at all we are get no values.  We get values for the log files, all other part of the application seem to be displaying the correct data.  &lt;/P&gt;

&lt;P&gt;This is under &lt;EM&gt;Mailbox Database Overview&lt;/EM&gt; &lt;/P&gt;

&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TH&gt;Database&lt;/TH&gt;&lt;TH&gt;MailboxStore&lt;/TH&gt;&lt;TH&gt;DatabaseSize(MB)&lt;/TH&gt;&lt;TH&gt;DBFreeSpace(%)&lt;/TH&gt;&lt;TH&gt;LogSize(MB)&lt;/TH&gt;&lt;TH&gt;LogFreeSpace(%)&lt;/TH&gt;&lt;/TR&gt;
&lt;TR&gt;&lt;TD&gt;MB-­Net-­01&lt;/TD&gt;&lt;TD&gt;Juno&lt;/TD&gt;&lt;TD&gt;0.00&lt;/TD&gt;&lt;TD&gt;72.61&lt;/TD&gt;&lt;TD&gt;33.00&lt;/TD&gt;&lt;TD&gt;94.29&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;

&lt;P&gt;Anyone have any ideas on how to correct this?&lt;/P&gt;

&lt;P&gt;Thanks&lt;BR /&gt;
Kevin  &lt;/P&gt;</description>
      <pubDate>Thu, 25 Oct 2012 16:26:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-for-Exchange-Database-information-not-showing/m-p/102997#M21627</guid>
      <dc:creator>deepcovelabs</dc:creator>
      <dc:date>2012-10-25T16:26:42Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk for Exchange - Database information not  showing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-for-Exchange-Database-information-not-showing/m-p/102998#M21628</link>
      <description>&lt;P&gt;I need a little more information on the environment you are running in to be able to ask a follow-questions appropriate to diagnose.  If you have a support contract, then follow up through a support call.  If not:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;What version of the App are you running? &lt;/LI&gt;
&lt;LI&gt;What version of Exchange is running on the server in question?&lt;/LI&gt;
&lt;LI&gt;What version of Splunk Universal Forwarder are you running on your mailbox store?&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Thu, 25 Oct 2012 16:31:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-for-Exchange-Database-information-not-showing/m-p/102998#M21628</guid>
      <dc:creator>ahall_splunk</dc:creator>
      <dc:date>2012-10-25T16:31:02Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk for Exchange - Database information not  showing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-for-Exchange-Database-information-not-showing/m-p/102999#M21629</link>
      <description>&lt;P&gt;Sorry about not including the version info:&lt;/P&gt;

&lt;P&gt;-Splunk: version 4.3.4, build 136012&lt;BR /&gt;
-Splunk for Exchange: v1.1.6&lt;BR /&gt;
-Exchange 2010 SP2: v14.2 build 247.5&lt;BR /&gt;
-Splunk Forwarder Win_x64: version 4.3.4, build 136012&lt;/P&gt;</description>
      <pubDate>Thu, 25 Oct 2012 18:54:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-for-Exchange-Database-information-not-showing/m-p/102999#M21629</guid>
      <dc:creator>deepcovelabs</dc:creator>
      <dc:date>2012-10-25T18:54:41Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk for Exchange - Database information not  showing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-for-Exchange-Database-information-not-showing/m-p/103000#M21630</link>
      <description>&lt;P&gt;The Exchange 2010 SP2 is likely the cause.  As detailed in the documentation (specifically: &lt;A href="http://docs.splunk.com/Documentation/MSExchange/2.0/DeployMSX/IssueswithSplunkAppforMSExchangeandMSExchange2010SP2"&gt;here&lt;/A&gt;), upgrading to SP2 sometimes (actually, most of the time) turns off the Exchange cmdlets, causing a loss of information.  That same page also contains a link to a blog post about a fix for the issue.&lt;/P&gt;

&lt;P&gt;A good test is to log onto your mailbox store, bring up the Exchange Powershell and run &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Get-MailboxServer -Identity $env:ComputerName
Get-MailboxDatabase -server $env:ComputerName -Status
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;These are the two Exchange cmdlets that give us the information you are looking for.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Oct 2012 18:59:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-for-Exchange-Database-information-not-showing/m-p/103000#M21630</guid>
      <dc:creator>ahall_splunk</dc:creator>
      <dc:date>2012-10-25T18:59:43Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk for Exchange - Database information not  showing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-for-Exchange-Database-information-not-showing/m-p/103001#M21631</link>
      <description>&lt;P&gt;No worries - if the scripts are running without issue and the size of the database is showing up in the scripts, the dashboard should work.  &lt;/P&gt;

&lt;P&gt;The script you want to be concentrating your efforts on is the get-databasestats.ps1 script.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Oct 2012 21:44:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-for-Exchange-Database-information-not-showing/m-p/103001#M21631</guid>
      <dc:creator>ahall_splunk</dc:creator>
      <dc:date>2012-10-25T21:44:05Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk for Exchange - Database information not  showing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-for-Exchange-Database-information-not-showing/m-p/103002#M21632</link>
      <description>&lt;P&gt;The 2 powershell cmds work, and so did the work-around test command with the small change in path.&lt;/P&gt;

&lt;P&gt;I change this:&lt;BR /&gt;
&lt;EM&gt;cd "C:\Program Files\SplunkUniversalForwarder\etc\apps\TA-Exchange-2010-MailboxStore"&lt;BR /&gt;
"C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe" cmd exchangepowershell.cmd get-hoststats.ps1&lt;/EM&gt;&lt;/P&gt;

&lt;P&gt;to this:&lt;BR /&gt;
cd "C:\Program Files\SplunkUniversalForwarder\etc\apps\TA-Exchange-2010-MailboxStore"&lt;BR /&gt;
"C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe" cmd .\bin\exchangepowershell.cmd get-hoststats.ps1&lt;/P&gt;

&lt;P&gt;result is as expected: white text result&lt;/P&gt;</description>
      <pubDate>Thu, 25 Oct 2012 21:49:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-for-Exchange-Database-information-not-showing/m-p/103002#M21632</guid>
      <dc:creator>deepcovelabs</dc:creator>
      <dc:date>2012-10-25T21:49:37Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk for Exchange - Database information not  showing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-for-Exchange-Database-information-not-showing/m-p/103003#M21633</link>
      <description>&lt;P&gt;Hmmm...  I had a look at the &lt;STRONG&gt;&lt;EM&gt;get-databasestats.ps1&lt;/EM&gt;&lt;/STRONG&gt; and I don't see any object Member with DatabaseSize.  I'll keep digging&lt;/P&gt;</description>
      <pubDate>Thu, 25 Oct 2012 22:19:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-for-Exchange-Database-information-not-showing/m-p/103003#M21633</guid>
      <dc:creator>deepcovelabs</dc:creator>
      <dc:date>2012-10-25T22:19:56Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk for Exchange - Database information not  showing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-for-Exchange-Database-information-not-showing/m-p/103004#M21634</link>
      <description>&lt;P&gt;If you do a search for eventtype=msexchange-database-stats then the number you want is in the FileSize field.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Oct 2012 22:24:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-for-Exchange-Database-information-not-showing/m-p/103004#M21634</guid>
      <dc:creator>ahall_splunk</dc:creator>
      <dc:date>2012-10-25T22:24:45Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk for Exchange - Database information not  showing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-for-Exchange-Database-information-not-showing/m-p/103005#M21635</link>
      <description>&lt;P&gt;to me this looked like a code error, I guess I am wrong:&lt;/P&gt;

&lt;P&gt;$EdbSize = ($EdbFilePath.PathName | Get-ChildItem).Length&lt;/P&gt;

&lt;P&gt;Shouldn't it be:&lt;/P&gt;

&lt;P&gt;$EdbSize = (&lt;STRONG&gt;&lt;EM&gt;$Database.&lt;/EM&gt;&lt;/STRONG&gt;EdbFilePath.PathName | Get-ChildItem).Length&lt;/P&gt;</description>
      <pubDate>Fri, 26 Oct 2012 23:09:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-for-Exchange-Database-information-not-showing/m-p/103005#M21635</guid>
      <dc:creator>deepcovelabs</dc:creator>
      <dc:date>2012-10-26T23:09:10Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk for Exchange - Database information not  showing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-for-Exchange-Database-information-not-showing/m-p/103006#M21636</link>
      <description>&lt;P&gt;Im just looking at the script now.  I do believe you are right.  Its correct in the 2007 and 2013 Exchange scripts.  I'll correct it here and it will go out with the next release.  Feel free to edit the script as you suggested.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Oct 2012 23:19:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-for-Exchange-Database-information-not-showing/m-p/103006#M21636</guid>
      <dc:creator>ahall_splunk</dc:creator>
      <dc:date>2012-10-26T23:19:34Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk for Exchange - Database information not  showing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-for-Exchange-Database-information-not-showing/m-p/103007#M21637</link>
      <description>&lt;P&gt;Thanks...&lt;/P&gt;

&lt;P&gt;I made the edit on the script on friday and we are now seeing the value being populated.  Thanks for your help.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Oct 2012 16:10:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-for-Exchange-Database-information-not-showing/m-p/103007#M21637</guid>
      <dc:creator>deepcovelabs</dc:creator>
      <dc:date>2012-10-29T16:10:06Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk for Exchange - Database information not  showing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-for-Exchange-Database-information-not-showing/m-p/103008#M21638</link>
      <description>&lt;P&gt;Side question: What script does DNSBL Reputation relay on?&lt;/P&gt;</description>
      <pubDate>Mon, 29 Oct 2012 16:11:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-for-Exchange-Database-information-not-showing/m-p/103008#M21638</guid>
      <dc:creator>deepcovelabs</dc:creator>
      <dc:date>2012-10-29T16:11:32Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk for Exchange - Database information not  showing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-for-Exchange-Database-information-not-showing/m-p/103009#M21639</link>
      <description>&lt;P&gt;I posted v2.0.1 of the Splunk app for Exchange that has this fix in it as well.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Oct 2012 16:11:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-for-Exchange-Database-information-not-showing/m-p/103009#M21639</guid>
      <dc:creator>ahall_splunk</dc:creator>
      <dc:date>2012-10-29T16:11:42Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk for Exchange - Database information not  showing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-for-Exchange-Database-information-not-showing/m-p/103010#M21640</link>
      <description>&lt;P&gt;DNSBL Reputation relay is in the TA-SMTP-Reputation&lt;/P&gt;</description>
      <pubDate>Mon, 29 Oct 2012 16:12:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-for-Exchange-Database-information-not-showing/m-p/103010#M21640</guid>
      <dc:creator>ahall_splunk</dc:creator>
      <dc:date>2012-10-29T16:12:30Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk for Exchange - Database information not  showing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-for-Exchange-Database-information-not-showing/m-p/103011#M21641</link>
      <description>&lt;P&gt;Thanks for all the help.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Oct 2012 16:38:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-for-Exchange-Database-information-not-showing/m-p/103011#M21641</guid>
      <dc:creator>deepcovelabs</dc:creator>
      <dc:date>2012-10-29T16:38:43Z</dc:date>
    </item>
  </channel>
</rss>

