All Apps and Add-ons

Not collecting windows event logs (application/security/Exchange Auditing) with Microsoft Exchange app

cnikitaras
Explorer

I recently deployed the Exchange app in my environment and I'm not collecting data from the application, security, and Exchange auditing logs. Per the documentation, this data should be collected. I checked each TA and did not find stanzas for([WinEventLog:*]) in any of the inputs.conf files. Should these be included in the TAs, or is this something I need to add to an inputs.conf file? This seems to be affecting the POP3 and IMAP4 dashboards.

skylasam_splunk
Splunk Employee
Splunk Employee

Ok , got it.
Yes, you should do the following -
1. Download and deploy the Windows Add-on - http://apps.splunk.com/app/742/ - to the relevant machine from which you want to collect the data.
2. Copy the contents of stanzas for "WinEventLog://" from $SPLUNK_HOME\etc\apps\splunk_ta_windows\default to $SPLUNK_HOME\etc\apps\splunk_ta_windows\local and set disabled=0 on them.
3. Restart splunk.

0 Karma

cnikitaras
Explorer

Should these stanzas already be included in the Exchange app? I didn't find anywhere in the documentation that talked about downloading the Windows Add-on. It only referenced the supporting add-on for Active Directory. The Exchange Auditing stanza is also not listed in the Windows download which makes me think it should have been included in the app.

skylasam_splunk
Splunk Employee
Splunk Employee

Are you looking at the CAS performance dashboard at the IMAP and POP3 panel? Can you paste in the URL for the dashboard which is causing a problem for you?

0 Karma

cnikitaras
Explorer

No, the performance dashboard is displaying correctly. I'm referring to the "POP3 and IMAP4 Overview" dashboard under "Client Behavior". URL is: https://servername:8000/en-US/app/Splunk_for_Exchange/client_pop_imap.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...