Splunk Search

How to search for unused Exchange distribution lists?

sharmabr
New Member

Is there a search that can identify stale Exchange 2010 distribution lists that haven't been used recently (e.g., >90/180/270 days), perhaps based on message tracking logs over time? Thanks.

0 Karma

sundareshr
Legend
0 Karma

sharmabr
New Member

Yes, but it doesn't have this query natively in the app. I'm hoping someone has a creative way of piecing this together based on available Exchange log data.

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...

Get Early Access to AI Playbook Authoring: Apply for the Alpha Private Preview ...

Passionate about security automation? Apply now to our AI Playbook Authoring Alpha private preview ...

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...