All Apps and Add-ons

App for Microsoft Exchange Multiple CAS servers IIS Logs

mmodeefrc
New Member

Hi, I am running exchange 2010 and I am having trouble with the IIS logs from 2 of my servers. I have 2 in NJ and 1 in the UK, I am getting all the IIS logs from the CAS server in the UK but not the 2 CAS servers in NJ. They are all configured identically. I have verified the inputs are exactly the same on all the server.

I am fresh out of ideas, anything I should look for?

0 Karma

michael_sanchez
Path Finder

What is your architecture ? Do you use Universal forwarders to get the IIS logs ? Do your files appears in the TailingProcessor:FileStatus ? (check https://localhost:8089/services/admin/inputstatus/TailingProcessor:FileStatus)

If everything is ok on the CAS servers and if you receive others events on the indexer, it means that you should check the configuration of your indexer. Do you have some nullQueue configuration in a props.conf file ?

0 Karma

techslate
New Member

Does this article on troubleshooting iis logs.

0 Karma

mmodeefrc
New Member

I did check all that and there are no firewalls enabled. I am getting other data from that server, but just not the IIS logs.

0 Karma

jbernt_splunk
Splunk Employee
Splunk Employee

Are other data inputs flowing in from the 2 CAS servers such as event logs, security, etc.? Have you checked the firewall rules between your NJ servers and the Splunk environment?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...