Getting Data In

Exchange Add-On Duplicated Logs

caroline_fortun
Explorer

Hello,

I installed splunk universal forwarder and the Exchange2010-Mailbox app to collect Exchange Auditing data.
I noticed that every time Splunk executes the exchange script it´s getting the data over and over again. The data is being duplicated.

Is there anything I did wrong? I just installed Universal Forwarder and copied the Exchange add on folder inside splunk app folder.

Regards,
Caroline Fortunato

Tags (2)
0 Karma
1 Solution

ahall_splunk
Splunk Employee
Splunk Employee

Unfortunately, you don't say what version you have installed and how it was installed. The latest version should not do this. Prior versions had this bug.

View solution in original post

0 Karma

ahall_splunk
Splunk Employee
Splunk Employee

That message is fairly normal in a stable system that doesn't see a lot of activity. However, I'm no closer to understanding why mailbox audit is duplicating events. I'll try to set up a repro.

In the meantime, I suggest disabling the mailbox audit data input.

0 Karma

caroline_fortun
Explorer

It´s an Exchange Server 2010 SP3 installed on a Windows Server 2008 R2.
The universal forwarder is running with System Local account.

I have logs like bellow at the source splunkd.log. There is nothing mentioning MailboxAudit.

"05-28-2014 15:19:52.474 -0300 WARN DateParserVerbose - Accepted time (Thu May 22 18:22:34 2014) is suspiciously far away from the previous event's time (Fri May 23 16:09:35 2014), but still accepted because it was extracted by the same pattern. Context: source::Powershell|host::maillab|MSExchange:2010:AdminAudit|274"

Regards,
Caroline Fortunato

0 Karma

ahall_splunk
Splunk Employee
Splunk Employee

What version of Exchange (including Service Pack) and what version of Windows is it running on? How are you running the Universal Forwarder? (Domain User or System Local)

Are there are logs in index=_internal sourec=*splunkd.log that pertain to the data input?

0 Karma

caroline_fortun
Explorer

I´m using Splunk 6.1.1. Universal Forwarder 6.1.1 and Exchange T.A 2.1.2

Regards,
Caroline Fortunato

0 Karma

ahall_splunk
Splunk Employee
Splunk Employee

Unfortunately, you don't say what version you have installed and how it was installed. The latest version should not do this. Prior versions had this bug.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...