All Apps and Add-ons

OWA logs not indexed completely?

corti77
Contributor

Hi,

I am trying to get OWA url into Splunk. I deployed the TA-Windows-Exchange-IIS changing the local input.conf according to our on-prem Exchange version, the stanza [monitor://C:\Program Files\Microsoft\Exchange Server\V15\Logging\Ews] 

After the deployment of the app, I see events coming in with the right sourcetype 

 

 

index=msexchange sourcetype="MSWindows:2013EWS:IIS"

 

 

but on those events I cannot see either the source IP or the URL.

I am trying to detect GET actions to the autodiscovery folder and I dont see on the received events either actions or url. 😕

any suggestion?

thanks!

 

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...