Getting Data In

Splunk App for Microsoft Exchange "2003"

paulf
Explorer

Hi,

Does the Splunk App for Microsoft Exchange support Exchange 2003 message tracking?

I have deployed the Exchange TA for 2003 but its only importing IIS Log data, looking at the inputs.conf there are no file monitors for Message Tracking data, yet they exist for later versions.

Thanks
Paul

Tags (1)
0 Karma

ahall_splunk
Splunk Employee
Splunk Employee

There is no support for Exchange 2003 in the Splunk App for Microsoft Exchange.

If you want to bring in the Message Tracking logs, then be aware that the message tracking logs are incomplete. Specifically, messages that originate and end on the same message store are never recorded. However, they are in the same general format as the message tracking logs for Exchange 2007 and 2010 - just different positions for the fields. Take a look in the props.conf / transforms.conf of the Splunk App for Microsoft Exchange to see an example of how to do it, then look at the first 5-6 lines of a typical message tracking log and match up the field names. This will provide you with an extraction.

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...