Getting Data In

Splunk App for Microsoft Exchange "2003"

paulf
Explorer

Hi,

Does the Splunk App for Microsoft Exchange support Exchange 2003 message tracking?

I have deployed the Exchange TA for 2003 but its only importing IIS Log data, looking at the inputs.conf there are no file monitors for Message Tracking data, yet they exist for later versions.

Thanks
Paul

Tags (1)
0 Karma

ahall_splunk
Splunk Employee
Splunk Employee

There is no support for Exchange 2003 in the Splunk App for Microsoft Exchange.

If you want to bring in the Message Tracking logs, then be aware that the message tracking logs are incomplete. Specifically, messages that originate and end on the same message store are never recorded. However, they are in the same general format as the message tracking logs for Exchange 2007 and 2010 - just different positions for the fields. Take a look in the props.conf / transforms.conf of the Splunk App for Microsoft Exchange to see an example of how to do it, then look at the first 5-6 lines of a typical message tracking log and match up the field names. This will provide you with an extraction.

0 Karma
Get Updates on the Splunk Community!

Modern way of developing distributed application using OTel

Recently, I had the opportunity to work on a complex microservice using Spring boot and Quarkus to develop a ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had 3 releases of new security content via the Enterprise Security ...

Archived Metrics Now Available for APAC and EMEA realms

We’re excited to announce the launch of Archived Metrics in Splunk Infrastructure Monitoring for our customers ...