Greetings,
We are running on-premise Splunk v 6.5.0 with Splunk App for Microsoft Exchange v3.4.0 with Exchange 2013. Some panels in the Splunk App for Microsoft Exchange is showing no data. I narrowed it down to empty results when it searches for `sourcetype="MSExchange:*:Topology"`. These events are fed from the universal forwarder on the exchange host with the Splunk Add-on for Microsoft Exchange. Here are the contents of its inputs.conf:
[http://pastebin.com/SYQG91U7][1]
The problem is that there are no 2013 specific stanzas for me to enable. Does anyone have a solution?
[1]: http://pastebin.com/SYQG91U7
↧