All Apps and Add-ons

Not collecting windows event logs (application/security/Exchange Auditing) with Microsoft Exchange app

cnikitaras
Explorer

I recently deployed the Exchange app in my environment and I'm not collecting data from the application, security, and Exchange auditing logs. Per the documentation, this data should be collected. I checked each TA and did not find stanzas for([WinEventLog:*]) in any of the inputs.conf files. Should these be included in the TAs, or is this something I need to add to an inputs.conf file? This seems to be affecting the POP3 and IMAP4 dashboards.

skylasam_splunk
Splunk Employee
Splunk Employee

Ok , got it.
Yes, you should do the following -
1. Download and deploy the Windows Add-on - http://apps.splunk.com/app/742/ - to the relevant machine from which you want to collect the data.
2. Copy the contents of stanzas for "WinEventLog://" from $SPLUNK_HOME\etc\apps\splunk_ta_windows\default to $SPLUNK_HOME\etc\apps\splunk_ta_windows\local and set disabled=0 on them.
3. Restart splunk.

0 Karma

cnikitaras
Explorer

Should these stanzas already be included in the Exchange app? I didn't find anywhere in the documentation that talked about downloading the Windows Add-on. It only referenced the supporting add-on for Active Directory. The Exchange Auditing stanza is also not listed in the Windows download which makes me think it should have been included in the app.

skylasam_splunk
Splunk Employee
Splunk Employee

Are you looking at the CAS performance dashboard at the IMAP and POP3 panel? Can you paste in the URL for the dashboard which is causing a problem for you?

0 Karma

cnikitaras
Explorer

No, the performance dashboard is displaying correctly. I'm referring to the "POP3 and IMAP4 Overview" dashboard under "Client Behavior". URL is: https://servername:8000/en-US/app/Splunk_for_Exchange/client_pop_imap.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...