Monitoring Splunk

Exchange AdminAudit logs - An unexpected error has occurred and a Watson dump is being generated

knadav
Explorer

Hi All,

When trying to pull AdminAudit logs from Exchange to Splunk we are only receiving the following log (Which is divided to 2 logs):

First log:

WARNING: An unexpected error has occurred and a Watson dump is being generated: Object reference not set to an instance

Second log:

of an object.

 

 

Can please someone explain how to resolve this issue and get proper admin audit logs from exchange?

Labels (4)
Tags (1)
0 Karma

Azeemering
Builder

Did you setup the splunk service in windows to run as a domain service account on the exchange server?

If yes, then assign that domain user account the relevant role within exchange server.

knadav
Explorer

Hi @Azeemering ,

What role is needed on the Exchange Management?

 

Thanks! 

0 Karma

knadav
Explorer

Hi,

Can you assist good sir? 

 

Thanks! 

0 Karma

knadav
Explorer

Hi,

Thank you for answering.

Which role is needed on the Exchange server? 

Thanks! 

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...