diff --git a/Log Analytics/ParsingAnIISSMTPLog b/Log Analytics/ParsingAnIISSMTPLog new file mode 100644 index 0000000..e1a39e6 --- /dev/null +++ b/Log Analytics/ParsingAnIISSMTPLog @@ -0,0 +1,2 @@ +SMTPLogs_CL +| parse RawData with Date " " Time " " CIP " " CSUserName " " SSiteName " " SComputerName " " SIP " " SPort " " CSMethod " " CSUriStem " " csuriquery " " scstatus " " scwin32status " " scbytes " " csbytes " " timetaken " " csversion " " cshost " " csUserAgent " " csCookie " " csReferer