Refine your search:

Hi
I installed splunk for Exchange, but I found my internal domain become unknown like
Username Mailbox Size (MB) %age Quota Usage
1 mdm-good1@UNKNOWN 4 0.185910000
2 mdm-good2@UNKNOWN 4 0.177800000
3 mdm-good3@UNKNOWN 4 0.17780000
4 ben@UNKNOWN 2 0.082708
5 mailuser@UNKNOWN 2 0.077490
6 administrator@UNKNOWN 1 0.00090064
7 goodadmin@UNKNOWN

Anyone can hint me what I did wrong?

asked 05 Mar '12, 23:57

keiichilam's gravatar image

keiichilam
313
accept rate: 0%


One Answer:

You did not set up your local/domain_aliases.csv file.

link

answered 31 May '12, 21:08

ahall_splunk's gravatar image

ahall_splunk
3.0k26
accept rate: 34%

I've created this file after initial setup, but it hasn't updated. Does this have to be in before receiving data?

(03 Jul '12, 20:49) mikelanghorst

No, it doesn't need to be there before receiving data - it's used as a lookup, which is search time. Would you mind posting your domain_aliases.csv file?

(04 Jul '12, 08:36) ahall_splunk
Post your answer
toggle preview

Follow this question

Log In to enable email subscriptions

RSS:

Answers

Answers + Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "Title")
  • image?![alt text](/path/img.jpg "Title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Tags:

Asked: 05 Mar '12, 23:57

Seen: 705 times

Last updated: 04 Jul '12, 08:36

Copyright © 2005-2012 Splunk Inc. All rights reserved.