All my dashboards in the Splunk App for Exchange are reporting this error.
I've taken a look at the lookup definition but am not sure how to solve the issue.
I have rebuilt the lookups multiple times through the app's guided setup, but the error remains.
... View more
I am setting up the Splunk App for Exchange. I have plenty of data coming in with a sourcetype of "MSExchange*" however the guided setup cannot find the events and fails.
Using index="msexchange" in a search retrieves all the events but what is keeping the search failing by only entering sourcetype?
I've checked the configuration files for all the apps and they seem fine according to Splunk documentation.
... View more