Getting Data In

Exchange Add-On Duplicated Logs

caroline_fortun
Explorer

Hello,

I installed splunk universal forwarder and the Exchange2010-Mailbox app to collect Exchange Auditing data.
I noticed that every time Splunk executes the exchange script it´s getting the data over and over again. The data is being duplicated.

Is there anything I did wrong? I just installed Universal Forwarder and copied the Exchange add on folder inside splunk app folder.

Regards,
Caroline Fortunato

Tags (2)
0 Karma
1 Solution

ahall_splunk
Splunk Employee
Splunk Employee

Unfortunately, you don't say what version you have installed and how it was installed. The latest version should not do this. Prior versions had this bug.

View solution in original post

0 Karma

ahall_splunk
Splunk Employee
Splunk Employee

That message is fairly normal in a stable system that doesn't see a lot of activity. However, I'm no closer to understanding why mailbox audit is duplicating events. I'll try to set up a repro.

In the meantime, I suggest disabling the mailbox audit data input.

0 Karma

caroline_fortun
Explorer

It´s an Exchange Server 2010 SP3 installed on a Windows Server 2008 R2.
The universal forwarder is running with System Local account.

I have logs like bellow at the source splunkd.log. There is nothing mentioning MailboxAudit.

"05-28-2014 15:19:52.474 -0300 WARN DateParserVerbose - Accepted time (Thu May 22 18:22:34 2014) is suspiciously far away from the previous event's time (Fri May 23 16:09:35 2014), but still accepted because it was extracted by the same pattern. Context: source::Powershell|host::maillab|MSExchange:2010:AdminAudit|274"

Regards,
Caroline Fortunato

0 Karma

ahall_splunk
Splunk Employee
Splunk Employee

What version of Exchange (including Service Pack) and what version of Windows is it running on? How are you running the Universal Forwarder? (Domain User or System Local)

Are there are logs in index=_internal sourec=*splunkd.log that pertain to the data input?

0 Karma

caroline_fortun
Explorer

I´m using Splunk 6.1.1. Universal Forwarder 6.1.1 and Exchange T.A 2.1.2

Regards,
Caroline Fortunato

0 Karma

ahall_splunk
Splunk Employee
Splunk Employee

Unfortunately, you don't say what version you have installed and how it was installed. The latest version should not do this. Prior versions had this bug.

0 Karma
Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...