<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: App for Microsoft Exchange Multiple CAS servers IIS Logs in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/App-for-Microsoft-Exchange-Multiple-CAS-servers-IIS-Logs/m-p/54098#M70286</link>
    <description>&lt;P&gt;I did check all that and there are no firewalls enabled.  I am getting other data from that server, but just not the IIS logs.&lt;/P&gt;</description>
    <pubDate>Tue, 04 Jun 2013 21:08:32 GMT</pubDate>
    <dc:creator>mmodeefrc</dc:creator>
    <dc:date>2013-06-04T21:08:32Z</dc:date>
    <item>
      <title>App for Microsoft Exchange Multiple CAS servers IIS Logs</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/App-for-Microsoft-Exchange-Multiple-CAS-servers-IIS-Logs/m-p/54096#M70284</link>
      <description>&lt;P&gt;Hi, I am running exchange 2010 and I am having trouble with the IIS logs from 2 of my servers.  I have 2 in NJ and 1 in the UK, I am getting all the IIS logs from the CAS server in the UK but not the 2 CAS servers in NJ.  They are all configured identically.  I have verified the inputs are exactly the same on all the server.  &lt;/P&gt;

&lt;P&gt;I am fresh out of ideas, anything I should look for?&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jun 2013 22:56:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/App-for-Microsoft-Exchange-Multiple-CAS-servers-IIS-Logs/m-p/54096#M70284</guid>
      <dc:creator>mmodeefrc</dc:creator>
      <dc:date>2013-06-03T22:56:17Z</dc:date>
    </item>
    <item>
      <title>Re: App for Microsoft Exchange Multiple CAS servers IIS Logs</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/App-for-Microsoft-Exchange-Multiple-CAS-servers-IIS-Logs/m-p/54097#M70285</link>
      <description>&lt;P&gt;Are other data inputs flowing in from the 2 CAS servers such as event logs, security, etc.? Have you checked the firewall rules between your NJ servers and the Splunk environment?&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jun 2013 21:02:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/App-for-Microsoft-Exchange-Multiple-CAS-servers-IIS-Logs/m-p/54097#M70285</guid>
      <dc:creator>jbernt_splunk</dc:creator>
      <dc:date>2013-06-04T21:02:41Z</dc:date>
    </item>
    <item>
      <title>Re: App for Microsoft Exchange Multiple CAS servers IIS Logs</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/App-for-Microsoft-Exchange-Multiple-CAS-servers-IIS-Logs/m-p/54098#M70286</link>
      <description>&lt;P&gt;I did check all that and there are no firewalls enabled.  I am getting other data from that server, but just not the IIS logs.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jun 2013 21:08:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/App-for-Microsoft-Exchange-Multiple-CAS-servers-IIS-Logs/m-p/54098#M70286</guid>
      <dc:creator>mmodeefrc</dc:creator>
      <dc:date>2013-06-04T21:08:32Z</dc:date>
    </item>
    <item>
      <title>Re: App for Microsoft Exchange Multiple CAS servers IIS Logs</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/App-for-Microsoft-Exchange-Multiple-CAS-servers-IIS-Logs/m-p/54099#M70287</link>
      <description>&lt;P&gt;Does this article on troubleshooting &lt;A href="http://techslate.net/cas-server-and-using-and-troubleshooting-iis-log-files/"&gt;iis logs&lt;/A&gt;. &lt;/P&gt;</description>
      <pubDate>Fri, 28 Jun 2013 06:43:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/App-for-Microsoft-Exchange-Multiple-CAS-servers-IIS-Logs/m-p/54099#M70287</guid>
      <dc:creator>techslate</dc:creator>
      <dc:date>2013-06-28T06:43:28Z</dc:date>
    </item>
    <item>
      <title>Re: App for Microsoft Exchange Multiple CAS servers IIS Logs</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/App-for-Microsoft-Exchange-Multiple-CAS-servers-IIS-Logs/m-p/54100#M70288</link>
      <description>&lt;P&gt;What is your architecture ? Do you use Universal forwarders to get the IIS logs ? Do your files appears in the TailingProcessor:FileStatus ? (check &lt;A href="https://localhost:8089/services/admin/inputstatus/TailingProcessor:FileStatus"&gt;https://localhost:8089/services/admin/inputstatus/TailingProcessor:FileStatus&lt;/A&gt;)&lt;/P&gt;

&lt;P&gt;If everything is ok on the CAS servers and if you receive others events on the indexer, it means that you should check the configuration of your indexer. Do you have some nullQueue configuration in a props.conf file ?&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jun 2013 08:40:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/App-for-Microsoft-Exchange-Multiple-CAS-servers-IIS-Logs/m-p/54100#M70288</guid>
      <dc:creator>michael_sanchez</dc:creator>
      <dc:date>2013-06-28T08:40:10Z</dc:date>
    </item>
  </channel>
</rss>

