Getting Data In

Exchange App for Splunk

hiteshkanchan
Communicator

I have CAS, Hub and MBX logs (Application, System and Event Logs) which I got from a Microsoft Exchange server. Can I directly load it into the Exchange APP of splunk for understannding this data/log?.

If yes, can someone tell me which path can I copy this log into so that I can check the information or get the details from this logs.

Tags (3)
0 Karma

ahall_splunk
Splunk Employee
Splunk Employee

The Windows Event Logs contain hardly any of the information required to run the Splunk App for Microsoft Exchange. In addition to Exchange specific logs, such as the IIS logs and Message Tracking logs, the Splunk App for Microsoft Exchange requires access to in-memory data structures that it exposes via Powershell scripts. So, the answer is - unfortunately - no, you cannot just import the Windows Event Logs from an Exchange server and expect the app to work.

hiteshkanchan
Communicator

I got the IIS Logs and the Message Tracking Logs as well. Does this help? Can I copy these logs to any location of /etc/apps/Splunk_For_Exchange/ to understand or get information from this log.

Can I not proceed further without Power shell script info?
How does this info look or what extension or type does it have?

0 Karma

MarioM
Motivator

I think it might not be as useful and lots of data are from powershell scripts...

All is based on sourcetype you can have a look in the app's TAs inputs.conf:

Splunk_for_Exchange/appserver/addons/TA-*/default/inputs.conf
0 Karma

hiteshkanchan
Communicator

My requirement is, I actually want to see if I can make any sense out of the data logs that I got from an Microsoft Exchange. So was checking if I could put this logs(Event Logs + IIS logs + Message Tracking logs) into any log path of Splunk_for_Exchange/... to understand the data. Not sure if I can get data from powershell scripts. Any idea abt the location or type of this data.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Mastering Threat Intelligence in ES 8.5, Splunk AI Assistant v2, and More from Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Break the Build: Inside the KubeDoom Lounge at .conf26

    You step up to the machine. The pixelated corridors of a certain 1993 FPS load in front of you, EMP Pulse ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...