<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to ingest HttpProxy logs from Exchange? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-ingest-HttpProxy-logs-from-Exchange/m-p/642892#M109574</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have the need to detect basic authentication logons on our exchange on-prem system.&lt;/P&gt;&lt;P&gt;we have deployed the TA add-on for Exchange but it does not monitor a log file where I found the information I needed.&lt;/P&gt;&lt;P&gt;The log files are located in the path&amp;nbsp;E:\Program Files\Microsoft\Exchange Server\V15\Logging\HttpProxy\Mapi&lt;/P&gt;&lt;P&gt;I thought to add one stanza to monitor the log files in there but I don't know which source type should I use for it. I wonder if someone already create one that could be shared.&lt;/P&gt;&lt;P&gt;[monitor://E:\Program Files\Microsoft\Exchange Server\V15\Logging\HttpProxy\Mapi]&lt;BR /&gt;whitelist=\.log$|\.LOG$&lt;BR /&gt;time_before_close = 0&lt;BR /&gt;sourcetype= ???????????????&lt;BR /&gt;queue=parsingQueue&lt;BR /&gt;index=msexchange&lt;BR /&gt;disabled=false&lt;/P&gt;&lt;P&gt;many thanks.&lt;/P&gt;</description>
    <pubDate>Wed, 10 May 2023 17:18:00 GMT</pubDate>
    <dc:creator>corti77</dc:creator>
    <dc:date>2023-05-10T17:18:00Z</dc:date>
    <item>
      <title>How to ingest HttpProxy logs from Exchange?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-ingest-HttpProxy-logs-from-Exchange/m-p/642892#M109574</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have the need to detect basic authentication logons on our exchange on-prem system.&lt;/P&gt;&lt;P&gt;we have deployed the TA add-on for Exchange but it does not monitor a log file where I found the information I needed.&lt;/P&gt;&lt;P&gt;The log files are located in the path&amp;nbsp;E:\Program Files\Microsoft\Exchange Server\V15\Logging\HttpProxy\Mapi&lt;/P&gt;&lt;P&gt;I thought to add one stanza to monitor the log files in there but I don't know which source type should I use for it. I wonder if someone already create one that could be shared.&lt;/P&gt;&lt;P&gt;[monitor://E:\Program Files\Microsoft\Exchange Server\V15\Logging\HttpProxy\Mapi]&lt;BR /&gt;whitelist=\.log$|\.LOG$&lt;BR /&gt;time_before_close = 0&lt;BR /&gt;sourcetype= ???????????????&lt;BR /&gt;queue=parsingQueue&lt;BR /&gt;index=msexchange&lt;BR /&gt;disabled=false&lt;/P&gt;&lt;P&gt;many thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 10 May 2023 17:18:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-ingest-HttpProxy-logs-from-Exchange/m-p/642892#M109574</guid>
      <dc:creator>corti77</dc:creator>
      <dc:date>2023-05-10T17:18:00Z</dc:date>
    </item>
  </channel>
</rss>

