Hi,
Does the Splunk App for Microsoft Exchange support Exchange 2003 message tracking?
I have deployed the Exchange TA for 2003 but its only importing IIS Log data, looking at the inputs.conf there are no file monitors for Message Tracking data, yet they exist for later versions.
Thanks
Paul
There is no support for Exchange 2003 in the Splunk App for Microsoft Exchange.
If you want to bring in the Message Tracking logs, then be aware that the message tracking logs are incomplete. Specifically, messages that originate and end on the same message store are never recorded. However, they are in the same general format as the message tracking logs for Exchange 2007 and 2010 - just different positions for the fields. Take a look in the props.conf / transforms.conf of the Splunk App for Microsoft Exchange to see an example of how to do it, then look at the first 5-6 lines of a typical message tracking log and match up the field names. This will provide you with an extraction.