Splunk Search

Splunk for Exchange: Not indexing message tracking logs

SheridanCollege
Explorer

Splunk for Exchange v2.1.0 on Splunk v5.0.2 main search head and indexers. Running splunk universal forwarder v5.0.2 with TA-Exchange-2010-HubTransport on windows 2008R2 with exchange hub transport role.

My problem is that I'm not seeing the Message Tracking logs on the main search head. However, I do see perfmon, sourcetype=MSWindows:2008R2:IIS, sourcetype=MSExchange:2010:Topology, sourcetype=MSExchange:2010:ThrottlingPolicy logs from this host.

How do I troubleshoot this?


[monitor://E:\Exchange Server\MessageTracking]
whitelist=\.log$|\.LOG$
sourcetype=MSExchange:2010:MessageTracking
queue=parsingQueue
index=msexchange

disabled=false

c:\Program Files\SplunkUniversalForwarder\bin>splunk.exe list monitor -auth admin:changeme

Monitored Files:

E:\Exchange Server\MessageTracking

0 Karma
1 Solution

SheridanCollege
Explorer

The problem was that the message tracking logs were in a non-default location

View solution in original post

0 Karma

SheridanCollege
Explorer

The problem was that the message tracking logs were in a non-default location

0 Karma

rashid47010
Communicator

What does that mean
That log files were non default location

Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...