Getting Data In

Exchange Add-On Duplicated Logs

caroline_fortun
Explorer

Hello,

I installed splunk universal forwarder and the Exchange2010-Mailbox app to collect Exchange Auditing data.
I noticed that every time Splunk executes the exchange script it´s getting the data over and over again. The data is being duplicated.

Is there anything I did wrong? I just installed Universal Forwarder and copied the Exchange add on folder inside splunk app folder.

Regards,
Caroline Fortunato

Tags (2)
0 Karma
1 Solution

ahall_splunk
Splunk Employee
Splunk Employee

Unfortunately, you don't say what version you have installed and how it was installed. The latest version should not do this. Prior versions had this bug.

View solution in original post

0 Karma

ahall_splunk
Splunk Employee
Splunk Employee

That message is fairly normal in a stable system that doesn't see a lot of activity. However, I'm no closer to understanding why mailbox audit is duplicating events. I'll try to set up a repro.

In the meantime, I suggest disabling the mailbox audit data input.

0 Karma

caroline_fortun
Explorer

It´s an Exchange Server 2010 SP3 installed on a Windows Server 2008 R2.
The universal forwarder is running with System Local account.

I have logs like bellow at the source splunkd.log. There is nothing mentioning MailboxAudit.

"05-28-2014 15:19:52.474 -0300 WARN DateParserVerbose - Accepted time (Thu May 22 18:22:34 2014) is suspiciously far away from the previous event's time (Fri May 23 16:09:35 2014), but still accepted because it was extracted by the same pattern. Context: source::Powershell|host::maillab|MSExchange:2010:AdminAudit|274"

Regards,
Caroline Fortunato

0 Karma

ahall_splunk
Splunk Employee
Splunk Employee

What version of Exchange (including Service Pack) and what version of Windows is it running on? How are you running the Universal Forwarder? (Domain User or System Local)

Are there are logs in index=_internal sourec=*splunkd.log that pertain to the data input?

0 Karma

caroline_fortun
Explorer

I´m using Splunk 6.1.1. Universal Forwarder 6.1.1 and Exchange T.A 2.1.2

Regards,
Caroline Fortunato

0 Karma

ahall_splunk
Splunk Employee
Splunk Employee

Unfortunately, you don't say what version you have installed and how it was installed. The latest version should not do this. Prior versions had this bug.

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...