Getting Data In

Exchange Add-On Duplicated Logs

caroline_fortun
Explorer

Hello,

I installed splunk universal forwarder and the Exchange2010-Mailbox app to collect Exchange Auditing data.
I noticed that every time Splunk executes the exchange script it´s getting the data over and over again. The data is being duplicated.

Is there anything I did wrong? I just installed Universal Forwarder and copied the Exchange add on folder inside splunk app folder.

Regards,
Caroline Fortunato

Tags (2)
0 Karma
1 Solution

ahall_splunk
Splunk Employee
Splunk Employee

Unfortunately, you don't say what version you have installed and how it was installed. The latest version should not do this. Prior versions had this bug.

View solution in original post

0 Karma

ahall_splunk
Splunk Employee
Splunk Employee

That message is fairly normal in a stable system that doesn't see a lot of activity. However, I'm no closer to understanding why mailbox audit is duplicating events. I'll try to set up a repro.

In the meantime, I suggest disabling the mailbox audit data input.

0 Karma

caroline_fortun
Explorer

It´s an Exchange Server 2010 SP3 installed on a Windows Server 2008 R2.
The universal forwarder is running with System Local account.

I have logs like bellow at the source splunkd.log. There is nothing mentioning MailboxAudit.

"05-28-2014 15:19:52.474 -0300 WARN DateParserVerbose - Accepted time (Thu May 22 18:22:34 2014) is suspiciously far away from the previous event's time (Fri May 23 16:09:35 2014), but still accepted because it was extracted by the same pattern. Context: source::Powershell|host::maillab|MSExchange:2010:AdminAudit|274"

Regards,
Caroline Fortunato

0 Karma

ahall_splunk
Splunk Employee
Splunk Employee

What version of Exchange (including Service Pack) and what version of Windows is it running on? How are you running the Universal Forwarder? (Domain User or System Local)

Are there are logs in index=_internal sourec=*splunkd.log that pertain to the data input?

0 Karma

caroline_fortun
Explorer

I´m using Splunk 6.1.1. Universal Forwarder 6.1.1 and Exchange T.A 2.1.2

Regards,
Caroline Fortunato

0 Karma

ahall_splunk
Splunk Employee
Splunk Employee

Unfortunately, you don't say what version you have installed and how it was installed. The latest version should not do this. Prior versions had this bug.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...