Hi,
I want to forward Exchange admin logs to my Splunk server. I installed a universal forwarder on my Exchange server. Which configuration should I do in the GUI while selecting logs/log types?
There is a Splunk app for exchange. Did you see it?
Product brief:
http://www.splunk.com/en_us/solutions/solution-areas/it-operations-management/microsoft-infrastructu...
Download/overview:
https://splunkbase.splunk.com/app/1660/
It comes with documentation:
https://splunkbase.splunk.com/app/1660/#/documentation