Is it possible to use this with Splunk on Linux by running a splunk universal forwarder on the Exchange server to send the events to the Linux server?
Yes - you can run the Indexer and Search Head roles of Splunk on any system. Only the FACs need to be run on Exchange.
Yes - you can run the Indexer and Search Head roles of Splunk on any system. Only the FACs need to be run on Exchange.