All Apps and Add-ons

Splunk TA-Windows-Exchange-IIS vs sourcetype=IIS

BP9906
Builder

Hello,
I have the Splunk App for Exchange but Splunk documentation is unclear on how to handle my situation.
I have servers with IIS and thus IIS logs, so my generic ALL-WINDOWS server class detects the IIS logs and sets the sourcetype=iis so that all the fields get parsed properly.

The Splunk TA for Exchange IIS is here but obviously my Exchange_IIS Serverclass is lesser precedence. Regardless, it doesnt make sense that TA-Windows-Exchange-IIS sets sourcetype=MSWindows:2008R2:IIS when it misses out on the dynamic IIS log parsing.

How can I make all the Exchange dashboards properly populate using sourcetype=iis?

Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...