All Apps and Add-ons
Highlighted

Why does "sourcetype="MSExchange*"" get no results but "sourcetype="MSExchange*" index="msexchange" " does?

Engager

I am setting up the Splunk App for Exchange. I have plenty of data coming in with a sourcetype of "MSExchange*" however the guided setup cannot find the events and fails.

Using index="msexchange" in a search retrieves all the events but what is keeping the search failing by only entering sourcetype?

I've checked the configuration files for all the apps and they seem fine according to Splunk documentation.

0 Karma
Highlighted

Re: Why does "sourcetype="MSExchange*"" get no results but "sourcetype="MSExchange*" index="msexchange" " does?

SplunkTrust
SplunkTrust
0 Karma