Downloaded the TA for Microsoft Exchange and noticed that Hub Transport doesn't contain any stanzas for Microsoft Exchange 2013. The stanza's only seem to be valid for Microsoft Exchange 2007 and Exchange 2010. If I deploy the TA to an Exchange 2013 server and then create an inputs.conf file to ingest the data the extraction doesn't do what it needs to do.
^^ In the above the sourcetype I expect not to work but if I don't have this in inputs.conf the sourcetype will be based on each LOG file.
When I looked at the transforms.conf in the default location I noted that Exchange 2013 is now using a "-" as opposed to a "_" in the log file. I have no experience with rewriting props and transforms files to fix this but it looks like it has been missed for Exchange 2013.
I have done the following to try and work (again no experience with trying to rewrite props, transforms but from what I have done I am closer to the picture as extraction is happening but incorrectly :(. Here is my configuration thus far. Can you please assist with the correct of the HubTransport TA to extract appropriately.
search = sourcetype=MSExchange:2013:MessageTracking (event-id="BADMAIL" OR event-id="DELIVER" OR event-id="FAIL" OR event-id="RECEIVE" OR event-id="SEND")
# alias fix for Email DM for ES
FIELDALIAS-user = sender-address AS user
FIELDALIAS-orig_dest = client-ip AS orig_dest
FIELDALIAS-dest_ip = server-ip AS dest_ip
FIELDALIAS-recipient_count = recipient-count AS recipient_count
FIELDALIAS-return_addr = return-path AS return_addr
FIELDALIAS-size = total-bytes AS size
FIELDALIAS-subject = message-subject AS subject
EVAL-orig_src = coalesce(original-client-ip,original-server-ip)
EVAL-protocol = "SMTP"
EVAL-vendor_product = "Microsoft Exchange"