I've installed the Splunk for Exchange app. One of the issues I'm having is with users showing up with @unknown.
I've created the domain_aliases.csv on the search head, with UNKNOWN, unknown, and our netbios name, and our domain name. But it's still showing mlanghorst@unknown.
I have 2 indexers and one search head. I've thought that maybe this needs to go on the indexer, but according to the docs I should only need to install the TA* apps there.
What am I missing here? Not sure yet what records that this search is keying off of.
... View more