I recently deployed the Exchange app in my environment and I'm not collecting data from the application, security, and Exchange auditing logs. Per the documentation, this data should be collected. I checked each TA and did not find stanzas for([WinEventLog:*]) in any of the inputs.conf files. Should these be included in the TAs, or is this something I need to add to an inputs.conf file? This seems to be affecting the POP3 and IMAP4 dashboards.
Ok , got it.
Yes, you should do the following -
1. Download and deploy the Windows Add-on - http://apps.splunk.com/app/742/ - to the relevant machine from which you want to collect the data.
2. Copy the contents of stanzas for "WinEventLog://" from $SPLUNK_HOME\etc\apps\splunk_ta_windows\default to $SPLUNK_HOME\etc\apps\splunk_ta_windows\local and set disabled=0 on them.
3. Restart splunk.
Should these stanzas already be included in the Exchange app? I didn't find anywhere in the documentation that talked about downloading the Windows Add-on. It only referenced the supporting add-on for Active Directory. The Exchange Auditing stanza is also not listed in the Windows download which makes me think it should have been included in the app.
Are you looking at the CAS performance dashboard at the IMAP and POP3 panel? Can you paste in the URL for the dashboard which is causing a problem for you?
No, the performance dashboard is displaying correctly. I'm referring to the "POP3 and IMAP4 Overview" dashboard under "Client Behavior". URL is: https://servername:8000/en-US/app/Splunk_for_Exchange/client_pop_imap.