All Apps and Add-ons

OWA logs not indexed completely?

corti77
Path Finder

Hi,

I am trying to get OWA url into Splunk. I deployed the TA-Windows-Exchange-IIS changing the local input.conf according to our on-prem Exchange version, the stanza [monitor://C:\Program Files\Microsoft\Exchange Server\V15\Logging\Ews] 

After the deployment of the app, I see events coming in with the right sourcetype 

 

 

index=msexchange sourcetype="MSWindows:2013EWS:IIS"

 

 

but on those events I cannot see either the source IP or the URL.

I am trying to detect GET actions to the autodiscovery folder and I dont see on the received events either actions or url. 😕

any suggestion?

thanks!

 

Labels (1)
0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!