<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Exchange App for Splunk in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Exchange-App-for-Splunk/m-p/41739#M7771</link>
    <description>&lt;P&gt;I got the IIS Logs and the Message Tracking Logs as well. Does this help? Can I copy these logs to any location of /etc/apps/Splunk_For_Exchange/ to understand or get information from this log. &lt;/P&gt;

&lt;P&gt;Can I not proceed further without Power shell script info?&lt;BR /&gt;
How does this info look or what extension or type does it have?&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 12:19:00 GMT</pubDate>
    <dc:creator>hiteshkanchan</dc:creator>
    <dc:date>2020-09-28T12:19:00Z</dc:date>
    <item>
      <title>Exchange App for Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Exchange-App-for-Splunk/m-p/41736#M7768</link>
      <description>&lt;P&gt;I have CAS, Hub and MBX logs (Application, System and Event Logs) which I got from a Microsoft Exchange server. Can I directly load it into the Exchange APP of splunk for understannding this data/log?.&lt;/P&gt;

&lt;P&gt;If yes, can someone tell me which path can I copy this log into so that I can check the information or get the details from this logs. &lt;/P&gt;</description>
      <pubDate>Wed, 22 Aug 2012 13:30:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Exchange-App-for-Splunk/m-p/41736#M7768</guid>
      <dc:creator>hiteshkanchan</dc:creator>
      <dc:date>2012-08-22T13:30:21Z</dc:date>
    </item>
    <item>
      <title>Re: Exchange App for Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Exchange-App-for-Splunk/m-p/41737#M7769</link>
      <description>&lt;P&gt;I think it might not be as useful and lots of data are from powershell scripts...&lt;/P&gt;

&lt;P&gt;All is based on sourcetype you can have a look in the app's TAs inputs.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Splunk_for_Exchange/appserver/addons/TA-*/default/inputs.conf
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 22 Aug 2012 14:10:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Exchange-App-for-Splunk/m-p/41737#M7769</guid>
      <dc:creator>MarioM</dc:creator>
      <dc:date>2012-08-22T14:10:18Z</dc:date>
    </item>
    <item>
      <title>Re: Exchange App for Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Exchange-App-for-Splunk/m-p/41738#M7770</link>
      <description>&lt;P&gt;The Windows Event Logs contain hardly any of the information required to run the Splunk App for Microsoft Exchange.  In addition to Exchange specific logs, such as the IIS logs and Message Tracking logs, the Splunk App for Microsoft Exchange requires access to in-memory data structures that it exposes via Powershell scripts.  So, the answer is - unfortunately - no, you cannot just import the Windows Event Logs from an Exchange server and expect the app to work.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Aug 2012 15:14:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Exchange-App-for-Splunk/m-p/41738#M7770</guid>
      <dc:creator>ahall_splunk</dc:creator>
      <dc:date>2012-08-22T15:14:49Z</dc:date>
    </item>
    <item>
      <title>Re: Exchange App for Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Exchange-App-for-Splunk/m-p/41739#M7771</link>
      <description>&lt;P&gt;I got the IIS Logs and the Message Tracking Logs as well. Does this help? Can I copy these logs to any location of /etc/apps/Splunk_For_Exchange/ to understand or get information from this log. &lt;/P&gt;

&lt;P&gt;Can I not proceed further without Power shell script info?&lt;BR /&gt;
How does this info look or what extension or type does it have?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 12:19:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Exchange-App-for-Splunk/m-p/41739#M7771</guid>
      <dc:creator>hiteshkanchan</dc:creator>
      <dc:date>2020-09-28T12:19:00Z</dc:date>
    </item>
    <item>
      <title>Re: Exchange App for Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Exchange-App-for-Splunk/m-p/41740#M7772</link>
      <description>&lt;P&gt;My requirement is, I actually want to see if I can make any sense out of the data logs that I got from an Microsoft Exchange. So was checking if I could put this logs(Event Logs + IIS logs + Message Tracking logs) into any log path of Splunk_for_Exchange/... to understand the data. Not sure if I can get data from powershell scripts. Any idea abt the location or type of this data.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 12:19:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Exchange-App-for-Splunk/m-p/41740#M7772</guid>
      <dc:creator>hiteshkanchan</dc:creator>
      <dc:date>2020-09-28T12:19:03Z</dc:date>
    </item>
  </channel>
</rss>

