Monitoring Splunk

Exchange AdminAudit logs - An unexpected error has occurred and a Watson dump is being generated

knadav
Explorer

Hi All,

When trying to pull AdminAudit logs from Exchange to Splunk we are only receiving the following log (Which is divided to 2 logs):

First log:

WARNING: An unexpected error has occurred and a Watson dump is being generated: Object reference not set to an instance

Second log:

of an object.

 

 

Can please someone explain how to resolve this issue and get proper admin audit logs from exchange?

Labels (4)
Tags (1)
0 Karma

Azeemering
Builder

Did you setup the splunk service in windows to run as a domain service account on the exchange server?

If yes, then assign that domain user account the relevant role within exchange server.

knadav
Explorer

Hi @Azeemering ,

What role is needed on the Exchange Management?

 

Thanks! 

0 Karma

knadav
Explorer

Hi,

Can you assist good sir? 

 

Thanks! 

0 Karma

knadav
Explorer

Hi,

Thank you for answering.

Which role is needed on the Exchange server? 

Thanks! 

0 Karma
Get Updates on the Splunk Community!

Technical Workshop Series: Splunk Data Management and SPL2 | Register here!

Hey, Splunk Community! Ready to take your data management skills to the next level? Join us for a 3-part ...

Spotting Financial Fraud in the Haystack: A Guide to Behavioral Analytics with Splunk

In today's digital financial ecosystem, security teams face an unprecedented challenge. The sheer volume of ...

Solve Problems Faster with New, Smarter AI and Integrations in Splunk Observability

Solve Problems Faster with New, Smarter AI and Integrations in Splunk Observability As businesses scale ...