Getting Data In

Splunk App for Microsoft Exchange "2003"

paulf
Explorer

Hi,

Does the Splunk App for Microsoft Exchange support Exchange 2003 message tracking?

I have deployed the Exchange TA for 2003 but its only importing IIS Log data, looking at the inputs.conf there are no file monitors for Message Tracking data, yet they exist for later versions.

Thanks
Paul

Tags (1)
0 Karma

ahall_splunk
Splunk Employee
Splunk Employee

There is no support for Exchange 2003 in the Splunk App for Microsoft Exchange.

If you want to bring in the Message Tracking logs, then be aware that the message tracking logs are incomplete. Specifically, messages that originate and end on the same message store are never recorded. However, they are in the same general format as the message tracking logs for Exchange 2007 and 2010 - just different positions for the fields. Take a look in the props.conf / transforms.conf of the Splunk App for Microsoft Exchange to see an example of how to do it, then look at the first 5-6 lines of a typical message tracking log and match up the field names. This will provide you with an extraction.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Data Management Digest – September 2026

    Welcome to the September 2026 edition of Data Management Digest! September brought a fresh wave of ...

Federated Search for CloudWatch Unified Data Store Is Generally Available

As organizations modernize their cloud environments, AWS workloads generate more security, operational, and ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...