Monitoring Splunk

Exchange AdminAudit logs - An unexpected error has occurred and a Watson dump is being generated

knadav
Explorer

Hi All,

When trying to pull AdminAudit logs from Exchange to Splunk we are only receiving the following log (Which is divided to 2 logs):

First log:

WARNING: An unexpected error has occurred and a Watson dump is being generated: Object reference not set to an instance

Second log:

of an object.

 

 

Can please someone explain how to resolve this issue and get proper admin audit logs from exchange?

Labels (4)
Tags (1)
0 Karma

Azeemering
Builder

Did you setup the splunk service in windows to run as a domain service account on the exchange server?

If yes, then assign that domain user account the relevant role within exchange server.

knadav
Explorer

Hi @Azeemering ,

What role is needed on the Exchange Management?

 

Thanks! 

0 Karma

knadav
Explorer

Hi,

Can you assist good sir? 

 

Thanks! 

0 Karma

knadav
Explorer

Hi,

Thank you for answering.

Which role is needed on the Exchange server? 

Thanks! 

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 2 releases of new security content via the ...

Announcing the 1st Round Champion’s Tribute Winners of the Great Resilience Quest

We are happy to announce the 20 lucky questers who are selected to be the first round of Champion's Tribute ...

We’ve Got Education Validation!

Are you feeling it? All the career-boosting benefits of up-skilling with Splunk? It’s not just a feeling, it's ...