I’m evaluating the Splunk app for Exchange. I noticed that the logs for the CAS/HubTransport were fairly large or least more than I was expecting. I have two CAS/HubTransport servers and 3 mailbox servers for about 700 employees. The CAS/HubTransport logs were about 15GB a piece with the largest index event being mswindows 2008 iis. I'm running Exchange 2010 and I put the TA's for Hubtransport, IIS, and CAS on the CAS boxes. I was expecting these logs to be a couple of GB at most. I'm I way off or would 30 GB be an expected index size for this?
... View more