Avatar of Naj Saqi
Naj SaqiFlag for Australia

asked on 

Which Exchange Logs should be collected for central logging solution?

Hi,

I am implementing a central logging solution using Elasticsearch, Logstash, and Kibana (ELK Stack). Now, which Exchange 2010 logs should be collected, message tracking, IIS, any other recommendations?
ExchangeMicrosoft IIS Web Server

Avatar of undefined
Last Comment
Steve
SOLUTION
Avatar of Hello World
Hello World

Blurred text
THIS SOLUTION IS ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
Avatar of Steve
Steve
Flag of United Kingdom of Great Britain and Northern Ireland image

depends what you are trying to monitor. there are various logs that exchange can produce but they all log a different element.
if you want to monitor for general issues, the event log is the best place as Exchange puts most issues in there by default.
if you want to monitor specific things consider  the individual logging element from each part of Exchange as noted above.
Avatar of Naj Saqi
Naj Saqi
Flag of Australia image

ASKER

Thanks for the replies. Currently, I am collecting message tracking which is highly recommended. What about IIS logs for OWA. I know Exchange can produce various logs that's why I asked a question in first place for recommendation.
SOLUTION
Avatar of Sudeep Sharma
Sudeep Sharma
Flag of India image

Blurred text
THIS SOLUTION IS ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
Avatar of Steve
Steve
Flag of United Kingdom of Great Britain and Northern Ireland image

I know Exchange can produce various logs that's why I asked a question in first place for recommendation.
yes,but we need to know what your intention is to make appropriate recommendations.
Are you monitoring health, performance, specific issues?
IE what are you looking for?
Avatar of Naj Saqi
Naj Saqi
Flag of Australia image

ASKER

yes,but we need to know what your intention is to make appropriate recommendations.
Are you monitoring health, performance, specific issues?
IE what are you looking for?

Well, it's not for monitoring health performance but for forensic investigation in case of any event.
ASKER CERTIFIED SOLUTION
Avatar of Steve
Steve
Flag of United Kingdom of Great Britain and Northern Ireland image

Blurred text
THIS SOLUTION IS ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
Avatar of Naj Saqi
Naj Saqi
Flag of Australia image

ASKER

Thanks Steve,

So, I should ship IIS, SmTP. and message tracking logs, right?
SOLUTION
Avatar of Steve
Steve
Flag of United Kingdom of Great Britain and Northern Ireland image

Blurred text
THIS SOLUTION IS ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
Exchange
Exchange

Exchange is the server side of a collaborative application product that is part of the Microsoft Server infrastructure. Exchange's major features include email, calendaring, contacts and tasks, support for mobile and web-based access to information, and support for data storage.

213K
Questions
--
Followers
--
Top Experts
Get a personalized solution from industry experts
Ask the experts
Read over 600 more reviews

TRUSTED BY

IBM logoIntel logoMicrosoft logoUbisoft logoSAP logo
Qualcomm logoCitrix Systems logoWorkday logoErnst & Young logo
High performer badgeUsers love us badge
LinkedIn logoFacebook logoX logoInstagram logoTikTok logoYouTube logo