We installed the forwarder in exchange.
Forwarder sending logs to the Splunk Enterprise search and reporting.
We can see the real-time logs and as well as last 2 month logs.
Splung showing last 2 months logs, before 2 month there is no logs,
we are running the splunk from last 3 years, historic logs are not available.
Hi ahmedkhanimran,
what's your question?
Bye.
Giuseppe