All Apps and Add-ons

Splunk App for Exchange - Errors

Kendo213
Communicator
  1. I'm having some issues identifying the problems with my Splunk App for Exchange install. For example, under Client Behavior -> Client Activity, OWA and ActiveSync are green, while EWS and Outlook Anywhere have big yellow exclamation points next to them. If I click on EWS I see data, so I know it's at least working. Outlook Anywhere isn't really in use in this test environment, but it would still be nice to know why these errors appear.

This is spamming the event logs: Cmdlet failed. Cmdlet Search-MailboxAuditLog, parameters {Identity=domain.com/User, LogonTypes={Owner, Delegate, Admin}, ShowDetails=True, StartDate=3/29/2013 10:40:46 AM}.

Cmdlet failed. Cmdlet Search-AdminAuditLog, parameters {StartDate=3/25/2013 9:34:54 PM}.

  1. The reputation portion is now working, but dnsbl.solid.net and singlebl.spamgrouper.com are timing out. Is there a way to edit the list of servers the reputation TA tries to hit?

  2. Another issue is the Non-Owner Mailbox Access Report. I've enabled auditing on a test user per the instructions, however it isn't working (No results found). Anyone ran into this?

  3. Distribution Lists Report is returning no information.

Any tips?

0 Karma

andykiely
Path Finder

You will see an exclaimation mark if there is no data coming into the relevant client activity, I dont use outlook anywhere so mine is the same whereas the other three are green.

To edit the list of reputation servers go into:

.\TA-SMTP-Reputation\bin\check_my_reputation.py and make your amends.

Not sure about your question 2 and question 3 I need an answer myself.

Regards

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...