Getting Data In

Exchange 2010 Mailbox Audit Logs

vikdiva
New Member

Is Splunk able to collect exchange 2010 mailbox audit logs from each mailbox and how? The mailbox audit logs are written within each application and stored on each mailbox. Since the mailbox audit logs are not written to windows event folder or a flat file can splunk collect these logs from the mailboxes to a central location and how can it do that?

Tags (1)
0 Karma

gpullis
Communicator

In version 2.1.2 of the "Splunk App for Microsoft Exchange", the TA-Exchange-2010-MailboxStore has a scripted input that collects the mailbox audit logs into a sourcetype called MSExchange:2010:MailboxAudit

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...