Getting Data In

Exchange Add-On Duplicated Logs

caroline_fortun
Explorer

Hello,

I installed splunk universal forwarder and the Exchange2010-Mailbox app to collect Exchange Auditing data.
I noticed that every time Splunk executes the exchange script it´s getting the data over and over again. The data is being duplicated.

Is there anything I did wrong? I just installed Universal Forwarder and copied the Exchange add on folder inside splunk app folder.

Regards,
Caroline Fortunato

Tags (2)
0 Karma
1 Solution

ahall_splunk
Splunk Employee
Splunk Employee

Unfortunately, you don't say what version you have installed and how it was installed. The latest version should not do this. Prior versions had this bug.

View solution in original post

0 Karma

ahall_splunk
Splunk Employee
Splunk Employee

That message is fairly normal in a stable system that doesn't see a lot of activity. However, I'm no closer to understanding why mailbox audit is duplicating events. I'll try to set up a repro.

In the meantime, I suggest disabling the mailbox audit data input.

0 Karma

caroline_fortun
Explorer

It´s an Exchange Server 2010 SP3 installed on a Windows Server 2008 R2.
The universal forwarder is running with System Local account.

I have logs like bellow at the source splunkd.log. There is nothing mentioning MailboxAudit.

"05-28-2014 15:19:52.474 -0300 WARN DateParserVerbose - Accepted time (Thu May 22 18:22:34 2014) is suspiciously far away from the previous event's time (Fri May 23 16:09:35 2014), but still accepted because it was extracted by the same pattern. Context: source::Powershell|host::maillab|MSExchange:2010:AdminAudit|274"

Regards,
Caroline Fortunato

0 Karma

ahall_splunk
Splunk Employee
Splunk Employee

What version of Exchange (including Service Pack) and what version of Windows is it running on? How are you running the Universal Forwarder? (Domain User or System Local)

Are there are logs in index=_internal sourec=*splunkd.log that pertain to the data input?

0 Karma

caroline_fortun
Explorer

I´m using Splunk 6.1.1. Universal Forwarder 6.1.1 and Exchange T.A 2.1.2

Regards,
Caroline Fortunato

0 Karma

ahall_splunk
Splunk Employee
Splunk Employee

Unfortunately, you don't say what version you have installed and how it was installed. The latest version should not do this. Prior versions had this bug.

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...