# Exchange Message Tracking

**URL:** <https://discuss.elastic.co/t/exchange-message-tracking/89164>\
**Category:** Logstash\
**Created:** [June 13, 2017, 9:39am UTC](https://discuss.elastic.co/t/exchange-message-tracking/89164 "2017-06-13T09:39:04Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![teejayuu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/teejayuu/32/18356_2.png) [@teejayuu](https://discuss.elastic.co/u/teejayuu)\
**Post date:** [June 13, 2017, 9:39am UTC](https://discuss.elastic.co/t/exchange-message-tracking/89164/1 "2017-06-13T09:39:05Z")

</div>

Hi,  
I've been following this tutorial to get Exchange Message Tracking logs into an ELK stack on Windows ([https://elijahpaul.co.uk/analysing-exchange-2013-message-tracking-logs-using-elk-elasticsearch-logstash-kibana/](https://elijahpaul.co.uk/analysing-exchange-2013-message-tracking-logs-using-elk-elasticsearch-logstash-kibana/)). The ELK stack is working, but is not getting the logs into logstash.

Looking at the nxlog.log I am getting this, so I guess nxlog is working:

```
2017-06-13 09:40:00 INFO nxlog-ce-2.9.1716 started
2017-06-13 10:00:02 WARNING input file was deleted: F:\Program Files\Microsoft\Exchange Server\V15\TransportRoles\Logs\MessageTracking\MSGTRK2017051409-1.LOG

```

How can I check that logstash is receiving the logs?

Thanks  
Tony

---

<div class="post-metadata">

**Author:** ![teejayuu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/teejayuu/32/18356_2.png) [@teejayuu](https://discuss.elastic.co/u/teejayuu)\
**Post date:** [June 13, 2017, 10:18am UTC](https://discuss.elastic.co/t/exchange-message-tracking/89164/2 "2017-06-13T10:18:51Z")

</div>

Just restarted the logstash service and checked the logs and saw:

> [2017-06-13T10:52:03,029][INFO][logstash.inputs.beats] Beats inputs: Starting input listener {:address=\>"0.0.0.0:5044"}  
> [2017-06-13T10:52:03,108][INFO][logstash.pipeline] Pipeline main started  
> [2017-06-13T10:52:03,342][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}

Further investigation shows my logstash.json is the culprit:

> input {  
> beats {  
> port =\> 5044  
> type =\> "log"  
> }  
> }

> output {  
> elasticsearch {  
> hosts =\> "localhost:9200"  
> manage\_template =\> false  
> index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
> document\_type =\> "%{[@metadata][type]}"  
> }  
> }

I am not using Beats, so I guess that logstash is expecting Beats input. I have used multiple sources to build my ELK stack I guess that this is why I can't see any data.

Is there some documentation on how to create logstash.json to get input from nxLog?

Thanks  
Tony

---

<div class="post-metadata">

**Author:** ![Oozza](https://avatars.discourse-cdn.com/v4/letter/o/76d3ee/32.png) [@Oozza](https://discuss.elastic.co/u/Oozza)\
**Post date:** [June 13, 2017, 10:48am UTC](https://discuss.elastic.co/t/exchange-message-tracking/89164/3 "2017-06-13T10:48:54Z")

</div>

To check if Logstash is processing some events you can use [stats API](https://www.elastic.co/guide/en/logstash/current/node-stats-api.html). For example visit (or curl) this endpoint `localhost:9600/_stats?pretty=true`

To manually check what is the output of your config, you can let Logstash write events to console using this output:

```
output {
  stdout { codec => rubydebug }
}

```

At first you will need to setup `input` according to how is Exchange configured. Do you want to read lines from file ? On same computer where logstash resides or different one ? Or do you need to listen on tcp/udp port instead?

---

<div class="post-metadata">

**Author:** ![teejayuu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/teejayuu/32/18356_2.png) [@teejayuu](https://discuss.elastic.co/u/teejayuu)\
**Post date:** [June 13, 2017, 11:04am UTC](https://discuss.elastic.co/t/exchange-message-tracking/89164/4 "2017-06-13T11:04:02Z")

</div>

Thanks Oozza.

I've sorted it - The logstash should have been looking at a different file (one that I'd created later).

Cheers  
Tony

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 11, 2017, 11:04am UTC](https://discuss.elastic.co/t/exchange-message-tracking/89164/5 "2017-07-11T11:04:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
