Getting Data In

Exchange admin audit logs

nuwan
New Member

Can splunk read exchange 2010 sp1 admin audit logs. I beleive exchange admin logs goes to a configured email. Does splunk exchange app reads the exchange admin logs
Thank you in advance

Tags (1)
0 Karma

ahall_splunk
Splunk Employee
Splunk Employee

Yes. Download the Splunk App for Microsoft Exchange - the TA-Exchange-2010-* technology add-ons that are included read the Admin Audit Logs from each server.

nuwan
New Member

Thank you.

0 Karma

micnuw2
New Member

I am also curious as it seems this issue isnt getting fixed. The short answer my Splunk team got from their Splunk rep was that the account that is forwarding to the Exchange app indexes needs to be in the same domain with organizational management role in Exchange XD. Im sorry but the expectation that an Exchange team using this app would give full open ended access to a service account just to forward admin audit logs is insane.

0 Karma

tomasmoser
Contributor

Hi,

I am curious when below bug will be fixed. It is related to Exchange 2016 admin audit log extraction.

2016-12-30 EXC-2052

read-audit-logs_2010_2013.ps1 failure. The search command search-adminauditlog used in read-audit-logs_2010_2013, does not work in PowerShell for the 2016 Exchange Server product. The MSExchange:2013:AdminAudit sourcetype will not display in Splunk platform searches.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

How to find the worst searches in your Splunk environment and how to fix them

Everyone knows Splunk is a powerful platform for running searches and doing data analytics. Your ...

Share Your Feedback: On Admin Config Service (ACS)!

Help Us Build a Better Admin Config Service Experience (ACS)   We Want Your Feedback on Admin Config Service ...

Build the Future of Agentic AI: Join the Splunk Agentic Ops Hackathon

AI is changing how teams investigate incidents, detect threats, automate workflows, and build intelligent ...