All Apps and Add-ons

Splunk TA-Windows-Exchange-IIS vs sourcetype=IIS


I have the Splunk App for Exchange but Splunk documentation is unclear on how to handle my situation.
I have servers with IIS and thus IIS logs, so my generic ALL-WINDOWS server class detects the IIS logs and sets the sourcetype=iis so that all the fields get parsed properly.

The Splunk TA for Exchange IIS is here but obviously my Exchange_IIS Serverclass is lesser precedence. Regardless, it doesnt make sense that TA-Windows-Exchange-IIS sets sourcetype=MSWindows:2008R2:IIS when it misses out on the dynamic IIS log parsing.

How can I make all the Exchange dashboards properly populate using sourcetype=iis?

Get Updates on the Splunk Community!

The Splunk Success Framework: Your Guide to Successful Splunk Implementations

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

Splunk Training for All: Meet Aspiring Cybersecurity Analyst, Marc Alicea

Splunk Education believes in the value of training and certification in today’s rapidly-changing data-driven ...

Investigate Security and Threat Detection with VirusTotal and Splunk Integration

As security threats and their complexities surge, security analysts deal with increased challenges and ...