<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Not getting complete MSExchange management event information ingested into Splunk. in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Not-getting-complete-MSExchange-management-event-information/m-p/459336#M99453</link>
    <description>&lt;P&gt;The configuration I have written to ingest MSExchange management data isn’t ingesting all the information contained in the event.&lt;BR /&gt;
Configuration deployed:&lt;BR /&gt;
[WinEventLog://MSExchange Management]&lt;BR /&gt;
index =&lt;BR /&gt;
sourcetype =&lt;/P&gt;

&lt;P&gt;We are receiving data in the instance but we are only getting general information associated with each event. Is there a way to get detailed information for an event into splunk?&lt;/P&gt;

&lt;P&gt;Let me know. &lt;/P&gt;</description>
    <pubDate>Thu, 22 Aug 2019 14:50:05 GMT</pubDate>
    <dc:creator>abhijit_mhatre</dc:creator>
    <dc:date>2019-08-22T14:50:05Z</dc:date>
    <item>
      <title>Not getting complete MSExchange management event information ingested into Splunk.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Not-getting-complete-MSExchange-management-event-information/m-p/459336#M99453</link>
      <description>&lt;P&gt;The configuration I have written to ingest MSExchange management data isn’t ingesting all the information contained in the event.&lt;BR /&gt;
Configuration deployed:&lt;BR /&gt;
[WinEventLog://MSExchange Management]&lt;BR /&gt;
index =&lt;BR /&gt;
sourcetype =&lt;/P&gt;

&lt;P&gt;We are receiving data in the instance but we are only getting general information associated with each event. Is there a way to get detailed information for an event into splunk?&lt;/P&gt;

&lt;P&gt;Let me know. &lt;/P&gt;</description>
      <pubDate>Thu, 22 Aug 2019 14:50:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Not-getting-complete-MSExchange-management-event-information/m-p/459336#M99453</guid>
      <dc:creator>abhijit_mhatre</dc:creator>
      <dc:date>2019-08-22T14:50:05Z</dc:date>
    </item>
    <item>
      <title>Re: Not getting complete MSExchange management event information ingested into Splunk.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Not-getting-complete-MSExchange-management-event-information/m-p/459337#M99454</link>
      <description>&lt;P&gt;Hi @abhijit_mhatre, what kind of details are you looking for ? Is that detail already in WinEventLog ? If so you should be able to fetch it &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; &lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2019 03:14:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Not-getting-complete-MSExchange-management-event-information/m-p/459337#M99454</guid>
      <dc:creator>DavidHourani</dc:creator>
      <dc:date>2019-08-23T03:14:37Z</dc:date>
    </item>
    <item>
      <title>Re: Not getting complete MSExchange management event information ingested into Splunk.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Not-getting-complete-MSExchange-management-event-information/m-p/459338#M99455</link>
      <description>&lt;P&gt;Hi @davidhourani,&lt;BR /&gt;
There are few additional details being generated on the MSexchange Server but the configuration is not ingesting all of it. It is only ingesting the general details.&lt;BR /&gt;
Is there a way to modify the configuration and have it pick everything being generated on the server.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2019 11:20:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Not-getting-complete-MSExchange-management-event-information/m-p/459338#M99455</guid>
      <dc:creator>abhijit_mhatre</dc:creator>
      <dc:date>2019-08-23T11:20:44Z</dc:date>
    </item>
    <item>
      <title>Re: Not getting complete MSExchange management event information ingested into Splunk.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Not-getting-complete-MSExchange-management-event-information/m-p/459339#M99456</link>
      <description>&lt;P&gt;Yes ! Of course. And first before adding anything new make sure you've followed this documentation to activate your required data inputs : &lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/MSExchange/3.5.2/Add-Ons/ConfigureTA-Exchange-IIS"&gt;https://docs.splunk.com/Documentation/MSExchange/3.5.2/Add-Ons/ConfigureTA-Exchange-IIS&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Sometimes its easy to miss activating inputs so you won't get everything. Double check that and then if you don't find what you're looking for let me know and we can work on making a new input.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2019 11:48:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Not-getting-complete-MSExchange-management-event-information/m-p/459339#M99456</guid>
      <dc:creator>DavidHourani</dc:creator>
      <dc:date>2019-08-23T11:48:04Z</dc:date>
    </item>
    <item>
      <title>Re: Not getting complete MSExchange management event information ingested into Splunk.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Not-getting-complete-MSExchange-management-event-information/m-p/459340#M99457</link>
      <description>&lt;P&gt;Hi @davidhourani,&lt;BR /&gt;
There is no configuration to ingest Msexchange Management logs in the TA-Exchange-IIS. I already have a configuration to ingest these logs, it is just that the complete information that can be seen in the event viewer is not getting ingested and only the general information in each event is being ingested.&lt;BR /&gt;
Let me know if there is a way( like having a script or a configuration) to ingest the complete information present in an event and not just the general information.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Aug 2019 10:13:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Not-getting-complete-MSExchange-management-event-information/m-p/459340#M99457</guid>
      <dc:creator>abhijit_mhatre</dc:creator>
      <dc:date>2019-08-27T10:13:42Z</dc:date>
    </item>
  </channel>
</rss>

