How to collect Windows Event Log-based data source such as "Exchange Auditing" log from Exchange 2007.
This Windows Event Log-based datasource does not exist by default.
1) Open InTrust Manager
2) Expand Configuration | Data Sources
3) Right-click and make "New Data Source"
4) Choose "Microsoft Windows Events"
5) Log name: "Exchange Auditing" (without the quotes). Choose "Remote, then Local" for resolution.
6) Click "OK" when prompted about not locating the log name.
7) Name will be "Exchange Auditing" (without the quotes). Hit "Next" and "Finish".
8) Update your the 2007 Exchange server gathering policy to include this datasource.
9) Save all the changes and run the job or wait for it to run on the schedule.