Hi
I installed splunk for Exchange,
but I found my internal domain become unknown like
Username Mailbox Size (MB) %age Quota Usage
1 mdm-good1@UNKNOWN 4 0.185910000
2 mdm-good2@UNKNOWN 4 0.177800000
3 mdm-good3@UNKNOWN 4 0.17780000
4 ben@UNKNOWN 2 0.082708
5 mailuser@UNKNOWN 2 0.077490
6 administrator@UNKNOWN 1 0.00090064
7 goodadmin@UNKNOWN
Anyone can hint me what I did wrong?
You did not set up your local/domain_aliases.csv file.
No, it doesn't need to be there before receiving data - it's used as a lookup, which is search time. Would you mind posting your domain_aliases.csv file?
I've created this file after initial setup, but it hasn't updated. Does this have to be in before receiving data?