Monitoring Splunk

Exchange AdminAudit logs - An unexpected error has occurred and a Watson dump is being generated

knadav
Explorer

Hi All,

When trying to pull AdminAudit logs from Exchange to Splunk we are only receiving the following log (Which is divided to 2 logs):

First log:

WARNING: An unexpected error has occurred and a Watson dump is being generated: Object reference not set to an instance

Second log:

of an object.

 

 

Can please someone explain how to resolve this issue and get proper admin audit logs from exchange?

Labels (4)
Tags (1)
0 Karma

Azeemering
Builder

Did you setup the splunk service in windows to run as a domain service account on the exchange server?

If yes, then assign that domain user account the relevant role within exchange server.

knadav
Explorer

Hi @Azeemering ,

What role is needed on the Exchange Management?

 

Thanks! 

0 Karma

knadav
Explorer

Hi,

Can you assist good sir? 

 

Thanks! 

0 Karma

knadav
Explorer

Hi,

Thank you for answering.

Which role is needed on the Exchange server? 

Thanks! 

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...