Splunk Search

Unable to chart Message Tracking or Client Behavior with Exchange App for Splunk

donwant
Explorer

I am using Exchange 2007 SP3 and it appears that my logs are flowing to the Splunk Instance. Some of the searches and reports do not seem to be working though. For instance I can get Capacity Planning / User population but not message volume. The message tracking menu shows no data as does most of the client behaviour. When I use the Search app I can see that the logs are showing and in the overview of the Exchange App it also shows a significant number of events being indexed.

I have added the local props.conf onto the Splunk Server instance. Do I need any of the other files as local to do the searches for the App?

0 Karma

ahall_splunk
Splunk Employee
Splunk Employee

Each input has a props.conf and transforms.conf for the particular data-set. Per the documentation, you need the specific fwd_* apps for the server role on the forwarder, then ALL the fwd_* apps + Splunk_for_Exchange on the indexer and search head.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...

Level Up Your Workflow: Mastering Splunk Cloud Management via Terraform

Tech Talk Recap   From Chaos to Control: Scaling Splunk Cloud with Infrastructure as Code Managing apps in ...