Hi,
I am trying to get OWA url into Splunk. I deployed the TA-Windows-Exchange-IIS changing the local input.conf according to our on-prem Exchange version, the stanza [monitor://C:\Program Files\Microsoft\Exchange Server\V15\Logging\Ews]
After the deployment of the app, I see events coming in with the right sourcetype
index=msexchange sourcetype="MSWindows:2013EWS:IIS"
but on those events I cannot see either the source IP or the URL.
I am trying to detect GET actions to the autodiscovery folder and I dont see on the received events either actions or url. 😕
any suggestion?
thanks!