Getting Data In

How to ingest HttpProxy logs from Exchange?

corti77
Contributor

Hi,

I have the need to detect basic authentication logons on our exchange on-prem system.

we have deployed the TA add-on for Exchange but it does not monitor a log file where I found the information I needed.

The log files are located in the path E:\Program Files\Microsoft\Exchange Server\V15\Logging\HttpProxy\Mapi

I thought to add one stanza to monitor the log files in there but I don't know which source type should I use for it. I wonder if someone already create one that could be shared.

[monitor://E:\Program Files\Microsoft\Exchange Server\V15\Logging\HttpProxy\Mapi]
whitelist=\.log$|\.LOG$
time_before_close = 0
sourcetype= ???????????????
queue=parsingQueue
index=msexchange
disabled=false

many thanks.

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...