# Monitor Microsoft Exchange Server 2013 logs

**URL:** <https://discuss.elastic.co/t/monitor-microsoft-exchange-server-2013-logs/152428>\
**Category:** Elasticsearch\
**Created:** [October 15, 2018, 6:17am UTC](https://discuss.elastic.co/t/monitor-microsoft-exchange-server-2013-logs/152428 "2018-10-15T06:17:30Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![zen.xen](https://avatars.discourse-cdn.com/v4/letter/z/e495f1/32.png) [@zen.xen](https://discuss.elastic.co/u/zen.xen)\
**Post date:** [October 15, 2018, 6:17am UTC](https://discuss.elastic.co/t/monitor-microsoft-exchange-server-2013-logs/152428/1 "2018-10-15T06:17:30Z")

</div>

Hello,  
I have installed ELK 6.4.0 in Windows environment, I configured winlogbeat for Windows logs and it works fine.  
Now I'd like to collect Exchange logs, so I have used filebeat but it is a little bit difficult to search some data because all data are in one field _message_. I found something like this [http://robwillis.info/2017/05/elk-5-setting-up-a-grok-filter-for-iis-logs/](http://robwillis.info/2017/05/elk-5-setting-up-a-grok-filter-for-iis-logs/) and I'd like to do the same with Exchange logs, is it possible, if yes, how do this?

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [October 15, 2018, 9:59am UTC](https://discuss.elastic.co/t/monitor-microsoft-exchange-server-2013-logs/152428/2 "2018-10-15T09:59:30Z")

</div>

Are you sending your data to logstash or to elasticsearch directly? if the latter, you could take a look at the [ingest node](https://www.elastic.co/guide/en/elasticsearch/reference/6.4/ingest.html) functionality of Elasticsearch.

--Alex

---

<div class="post-metadata">

**Author:** ![zen.xen](https://avatars.discourse-cdn.com/v4/letter/z/e495f1/32.png) [@zen.xen](https://discuss.elastic.co/u/zen.xen)\
**Post date:** [October 15, 2018, 10:32am UTC](https://discuss.elastic.co/t/monitor-microsoft-exchange-server-2013-logs/152428/3 "2018-10-15T10:32:18Z")

</div>

I am sending my data to elasticsearch directly. I opened link that you mentioned and try understand how to use it.  
In what file I configure / define a pipeline, processors?  
Could you give an example how to do this?

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [October 15, 2018, 10:54am UTC](https://discuss.elastic.co/t/monitor-microsoft-exchange-server-2013-logs/152428/4 "2018-10-15T10:54:05Z")

</div>

it's not a file, but rather an API call. The documentation includes a few examples. You might be interested in the [grok processor](https://www.elastic.co/guide/en/elasticsearch/reference/6.4/grok-processor.html) in particular.

Also, in order to easily debug things, I suggest you take a look at the [Simulate Pipeline API](https://www.elastic.co/guide/en/elasticsearch/reference/6.4/simulate-pipeline-api.html)

If you have further questions, please provide your full pipeline or better yet the full simulate pipeline API call.

---

<div class="post-metadata">

**Author:** ![zen.xen](https://avatars.discourse-cdn.com/v4/letter/z/e495f1/32.png) [@zen.xen](https://discuss.elastic.co/u/zen.xen)\
**Post date:** [October 15, 2018, 11:19am UTC](https://discuss.elastic.co/t/monitor-microsoft-exchange-server-2013-logs/152428/5 "2018-10-15T11:19:25Z")

</div>

That is the problem that I don't understand how to use that API, I'm not a programmer, I'd prefer to config a file with filter that "decompose" log file from Exchange to be more readable.  
I have read about the grok procesor and it could be a solution for my data.  
What should I do if I'd like send data to logstash?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 12, 2018, 11:22am UTC](https://discuss.elastic.co/t/monitor-microsoft-exchange-server-2013-logs/152428/6 "2018-11-12T11:22:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
