All Apps and Add-ons

Why does "sourcetype="MSExchange*"" get no results but "sourcetype="MSExchange*" index="msexchange" " does?


I am setting up the Splunk App for Exchange. I have plenty of data coming in with a sourcetype of "MSExchange*" however the guided setup cannot find the events and fails.

Using index="msexchange" in a search retrieves all the events but what is keeping the search failing by only entering sourcetype?

I've checked the configuration files for all the apps and they seem fine according to Splunk documentation.

0 Karma

Super Champion
0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to July and August Tech Talks, Office Hours, and Webinars!

Dive into our sizzling summer lineup for July and August Community Office Hours and Tech Talks. Scroll down to ...

Edge Processor Scaling, Energy & Manufacturing Use Cases, and More New Articles on ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Get More Out of Your Security Practice With a SIEM

Get More Out of Your Security Practice With a SIEMWednesday, July 31, 2024  |  11AM PT / 2PM ETREGISTER ...