Getting Data In

Splunk App for Microsoft Exchange "2003"

paulf
Explorer

Hi,

Does the Splunk App for Microsoft Exchange support Exchange 2003 message tracking?

I have deployed the Exchange TA for 2003 but its only importing IIS Log data, looking at the inputs.conf there are no file monitors for Message Tracking data, yet they exist for later versions.

Thanks
Paul

Tags (1)
0 Karma

ahall_splunk
Splunk Employee
Splunk Employee

There is no support for Exchange 2003 in the Splunk App for Microsoft Exchange.

If you want to bring in the Message Tracking logs, then be aware that the message tracking logs are incomplete. Specifically, messages that originate and end on the same message store are never recorded. However, they are in the same general format as the message tracking logs for Exchange 2007 and 2010 - just different positions for the fields. Take a look in the props.conf / transforms.conf of the Splunk App for Microsoft Exchange to see an example of how to do it, then look at the first 5-6 lines of a typical message tracking log and match up the field names. This will provide you with an extraction.

0 Karma
Get Updates on the Splunk Community!

New This Month in Splunk Observability Cloud - Metrics Usage Analytics, Enhanced K8s ...

The latest enhancements across the Splunk Observability portfolio deliver greater flexibility, better data and ...

Alerting Best Practices: How to Create Good Detectors

At their best, detectors and the alerts they trigger notify teams when applications aren’t performing as ...

Discover Powerful New Features in Splunk Cloud Platform: Enhanced Analytics, ...

Hey Splunky people! We are excited to share the latest updates in Splunk Cloud Platform 9.3.2408. In this ...