All Apps and Add-ons

Issues installing Splunk App for Microsoft Exchange on Search Head Cluster

davidjohnbecket
Path Finder

I am attempting to install the Splunk App for Microsoft Exchange on our search head cluster.

I drop the binaries into the C:\Program Files\Splunk\etc\shcluster\apps\splunk_app_microsoft_exchange folder on our deployment server and then push the app to the search head cluster by running the apply shcluster-bundle

The app looks to install on the search heads but when you try access the app from the app menu you get the following error on all search heads...

alt text

If you refresh the page then you occasionally get this error:

alt text

Any ideas?

0 Karma

Azeemering
Builder

Looking at the errors it seems that you did not install the other required apps...
Did you follow the following steps? :

https://docs.splunk.com/Documentation/MSExchange/3.4.4/DeployMSX/InstalltheSplunkAppforMicrosoftExch...

Install the Splunk Add-on for Windows on the search head cluster.
Install the Splunk Add-on for Microsoft Active Directory on the search head cluster.
Install the Splunk Add-on for Windows DNS on the search head cluster.
Install the Splunk Supporting Add-on for Active Directory on the search head cluster.
Install the Splunk App for Microsoft Exchange on the search head cluster.
On the search head cluster deployer, add the 'exchange_admin' role.
On the deployer, configure search peers that have Exchange and Windows data.
Run the first time setup on the deployer.
Push the app, add-ons, and configurations to the search head cluster members.
If you run Splunk Enterprise 6.3 on-premises, add the "exchange_admin" role to the user that runs the app on each search head cluster member.
Build lookups on a search head cluster member.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...