<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: newbie question: Exchange data input in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/newbie-question-Exchange-data-input/m-p/43113#M179124</link>
    <description>&lt;P&gt;found that the data is coming in, but going into main.  How do I get it into the Exchange index?&lt;/P&gt;</description>
    <pubDate>Thu, 03 May 2012 18:23:33 GMT</pubDate>
    <dc:creator>itrcb4</dc:creator>
    <dc:date>2012-05-03T18:23:33Z</dc:date>
    <item>
      <title>newbie question: Exchange data input</title>
      <link>https://community.splunk.com/t5/Splunk-Search/newbie-question-Exchange-data-input/m-p/43110#M179121</link>
      <description>&lt;P&gt;So I installed universal forwarder on my Exchange 2010 server, during install specified the splunk server's FQDN.&lt;/P&gt;

&lt;P&gt;On the web console - under "manager" - "forwarding and receiving" - receiving data - made sure there is an entry for prot 9997.&lt;/P&gt;

&lt;P&gt;Downloaded Splunk app for Exchange and Sideview.&lt;/P&gt;

&lt;P&gt;Problem - no data.  &lt;/P&gt;

&lt;P&gt;What should I do?&lt;/P&gt;</description>
      <pubDate>Thu, 03 May 2012 16:54:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/newbie-question-Exchange-data-input/m-p/43110#M179121</guid>
      <dc:creator>itrcb4</dc:creator>
      <dc:date>2012-05-03T16:54:22Z</dc:date>
    </item>
    <item>
      <title>Re: newbie question: Exchange data input</title>
      <link>https://community.splunk.com/t5/Splunk-Search/newbie-question-Exchange-data-input/m-p/43111#M179122</link>
      <description>&lt;P&gt;Did you create new inputs.conf files in the local directory for each technology add-on? See the &lt;A href="http://docs.splunk.com/Documentation/MSExchange/2.0/DeployMSX/Makeconfigurationchangestomatchyourexistingenvironment"&gt;Make configuration changes...&lt;/A&gt; topic in Deploy and Use the Splunk App for Microsoft Exchange.&lt;/P&gt;</description>
      <pubDate>Thu, 03 May 2012 17:07:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/newbie-question-Exchange-data-input/m-p/43111#M179122</guid>
      <dc:creator>ChrisG</dc:creator>
      <dc:date>2012-05-03T17:07:30Z</dc:date>
    </item>
    <item>
      <title>Re: newbie question: Exchange data input</title>
      <link>https://community.splunk.com/t5/Splunk-Search/newbie-question-Exchange-data-input/m-p/43112#M179123</link>
      <description>&lt;P&gt;Have you tested that DNS lookup is working from the mail server? It might be worth testing it with the IP instead. Also are there any firewalls blocking the ports on either machine or on the link between them?&lt;/P&gt;</description>
      <pubDate>Thu, 03 May 2012 17:07:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/newbie-question-Exchange-data-input/m-p/43112#M179123</guid>
      <dc:creator>Drainy</dc:creator>
      <dc:date>2012-05-03T17:07:40Z</dc:date>
    </item>
    <item>
      <title>Re: newbie question: Exchange data input</title>
      <link>https://community.splunk.com/t5/Splunk-Search/newbie-question-Exchange-data-input/m-p/43113#M179124</link>
      <description>&lt;P&gt;found that the data is coming in, but going into main.  How do I get it into the Exchange index?&lt;/P&gt;</description>
      <pubDate>Thu, 03 May 2012 18:23:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/newbie-question-Exchange-data-input/m-p/43113#M179124</guid>
      <dc:creator>itrcb4</dc:creator>
      <dc:date>2012-05-03T18:23:33Z</dc:date>
    </item>
    <item>
      <title>Re: newbie question: Exchange data input</title>
      <link>https://community.splunk.com/t5/Splunk-Search/newbie-question-Exchange-data-input/m-p/43114#M179125</link>
      <description>&lt;P&gt;Are you using version 1.1 of the app? In 1.1, the default is not to use main. See &lt;A href="http://docs.splunk.com/Documentation/MSExchange/2.0/DeployMSX/Whatdataarecollected"&gt;What data the Splunk App for Microsoft Exchange collects&lt;/A&gt; for an explanation of what goes where in the current release. If you are using 1.0, I suggest an upgrade.&lt;/P&gt;</description>
      <pubDate>Thu, 03 May 2012 18:52:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/newbie-question-Exchange-data-input/m-p/43114#M179125</guid>
      <dc:creator>ChrisG</dc:creator>
      <dc:date>2012-05-03T18:52:00Z</dc:date>
    </item>
    <item>
      <title>Re: newbie question: Exchange data input</title>
      <link>https://community.splunk.com/t5/Splunk-Search/newbie-question-Exchange-data-input/m-p/43115#M179126</link>
      <description>&lt;P&gt;It's the latest as I just downloaded it yesterday.&lt;/P&gt;

&lt;P&gt;Does it matter if I'm running Splunk free (eg. it restricts all data to main index)?  I want to use this to demo the value of Splunk before we make the leap / purchase.&lt;/P&gt;</description>
      <pubDate>Fri, 04 May 2012 15:01:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/newbie-question-Exchange-data-input/m-p/43115#M179126</guid>
      <dc:creator>itrcb4</dc:creator>
      <dc:date>2012-05-04T15:01:53Z</dc:date>
    </item>
    <item>
      <title>Re: newbie question: Exchange data input</title>
      <link>https://community.splunk.com/t5/Splunk-Search/newbie-question-Exchange-data-input/m-p/43116#M179127</link>
      <description>&lt;P&gt;Whether or not you're running Splunk Free should not affect where the data goes (although I am not sure that the Exchange App officially supports Splunk Free). I have talked to other customers who have installed version 1.1 and it sends the data to the correct three indexes (exchange, perfmon, and blackberry). There is a topic in the Exchange App documentation that tells you how to &lt;A href="http://docs.splunk.com/Documentation/MSExchange/latest/DeployMSX/Makeconfigurationchangestomatchyourexistingenvironment"&gt;make configuration changes to match your existing environment&lt;/A&gt;. But it seems as if there is something going on with your config--it's hard to diagnose with the information you've provided. You might want to try to reinstall the trial version of Splunk and follow the procedures in the Exchange App doc to reinstall that afterwards, see if it just clears up.&lt;/P&gt;</description>
      <pubDate>Fri, 04 May 2012 18:01:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/newbie-question-Exchange-data-input/m-p/43116#M179127</guid>
      <dc:creator>ChrisG</dc:creator>
      <dc:date>2012-05-04T18:01:19Z</dc:date>
    </item>
    <item>
      <title>Re: newbie question: Exchange data input</title>
      <link>https://community.splunk.com/t5/Splunk-Search/newbie-question-Exchange-data-input/m-p/43117#M179128</link>
      <description>&lt;P&gt;It's possible that when you installed the universal forwarder on your Exchange server, you enabled some of the default inputs. You also have to install the technology add-ons where you installed the forwarder. We've added a &lt;A href="http://docs.splunk.com/Documentation/MSExchange/2.0/DeployMSX/TroubleshoottheSplunkAppforMicrosoftExchange"&gt;troubleshooting topic&lt;/A&gt; to the docs to highlight these points.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jun 2012 20:17:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/newbie-question-Exchange-data-input/m-p/43117#M179128</guid>
      <dc:creator>ChrisG</dc:creator>
      <dc:date>2012-06-27T20:17:58Z</dc:date>
    </item>
  </channel>
</rss>

