<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why after switching from HF to UF, MSWindows:2012:IIS event no longer parses correctly? in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-after-switching-from-HF-to-UF-MSWindows-2012-IIS-event-no/m-p/592949#M12159</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/232899"&gt;@gitingua&lt;/a&gt;&amp;nbsp;- If you are using the &lt;A href="https://docs.splunk.com/Documentation/AddOns/released/MSIIS/Install" target="_blank"&gt;https://docs.splunk.com/Documentation/AddOns/released/MSIIS/Install&lt;/A&gt; Add-on for collecting and parsing the IIS logs then with UF Add-on requires to be installed on Indexers.&lt;/P&gt;&lt;P&gt;(I'm assuming UF is sending data directly to Indexers.)&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VatsalJagani_0-1649349715138.png" style="width: 765px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/18988iB31A9473A2128D78/image-dimensions/765x46?v=v2" width="765" height="46" role="button" title="VatsalJagani_0-1649349715138.png" alt="VatsalJagani_0-1649349715138.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I hope this helps, if it does consider upvoting!!!&lt;/P&gt;</description>
    <pubDate>Thu, 07 Apr 2022 16:42:21 GMT</pubDate>
    <dc:creator>VatsalJagani</dc:creator>
    <dc:date>2022-04-07T16:42:21Z</dc:date>
    <item>
      <title>Why after switching from HF to UF, MSWindows:2012:IIS event no longer parses correctly?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-after-switching-from-HF-to-UF-MSWindows-2012-IIS-event-no/m-p/592865#M12137</link>
      <description>&lt;P&gt;Hello colleagues. we recently switched from Splunk HF to UF. before this event with sourcetype = MSWindows:2012:IIS. parsed normal but after installation, something went wrong. and events in the spanner do not take all the fields from the logs&lt;/P&gt;</description>
      <pubDate>Thu, 07 Apr 2022 15:36:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-after-switching-from-HF-to-UF-MSWindows-2012-IIS-event-no/m-p/592865#M12137</guid>
      <dc:creator>gitingua</dc:creator>
      <dc:date>2022-04-07T15:36:32Z</dc:date>
    </item>
    <item>
      <title>Re: Why after switching from HF to UF, MSWindows:2012:IIS event no longer parses correctly?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-after-switching-from-HF-to-UF-MSWindows-2012-IIS-event-no/m-p/592949#M12159</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/232899"&gt;@gitingua&lt;/a&gt;&amp;nbsp;- If you are using the &lt;A href="https://docs.splunk.com/Documentation/AddOns/released/MSIIS/Install" target="_blank"&gt;https://docs.splunk.com/Documentation/AddOns/released/MSIIS/Install&lt;/A&gt; Add-on for collecting and parsing the IIS logs then with UF Add-on requires to be installed on Indexers.&lt;/P&gt;&lt;P&gt;(I'm assuming UF is sending data directly to Indexers.)&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VatsalJagani_0-1649349715138.png" style="width: 765px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/18988iB31A9473A2128D78/image-dimensions/765x46?v=v2" width="765" height="46" role="button" title="VatsalJagani_0-1649349715138.png" alt="VatsalJagani_0-1649349715138.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I hope this helps, if it does consider upvoting!!!&lt;/P&gt;</description>
      <pubDate>Thu, 07 Apr 2022 16:42:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-after-switching-from-HF-to-UF-MSWindows-2012-IIS-event-no/m-p/592949#M12159</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2022-04-07T16:42:21Z</dc:date>
    </item>
    <item>
      <title>Re: Why after switching from HF to UF, MSWindows:2012:IIS event no longer parses correctly?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-after-switching-from-HF-to-UF-MSWindows-2012-IIS-event-no/m-p/593070#M12165</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/93915"&gt;@VatsalJagani&lt;/a&gt;&amp;nbsp; Hi. We use the app&amp;nbsp;&lt;A href="https://splunkbase.splunk.com/app/3225/" target="_blank" rel="noopener"&gt;https://splunkbase.splunk.com/app/3225/&lt;/A&gt;&lt;BR /&gt;The problem is that there is a sourcetype=&lt;SPAN class=""&gt;MSWindows:2012:IIS&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;But it is not described in the props file, it does not parse events, do you think need to change the application?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Apr 2022 08:10:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-after-switching-from-HF-to-UF-MSWindows-2012-IIS-event-no/m-p/593070#M12165</guid>
      <dc:creator>gitingua</dc:creator>
      <dc:date>2022-04-08T08:10:26Z</dc:date>
    </item>
    <item>
      <title>Re: Why after switching from HF to UF, MSWindows:2012:IIS event no longer parses correctly?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-after-switching-from-HF-to-UF-MSWindows-2012-IIS-event-no/m-p/593076#M12166</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/232899"&gt;@gitingua&lt;/a&gt;&amp;nbsp;- I would install the Add-on on Indexers still because it seems like Add-on definitely has some parsing configuration. Make sure to put Add-on on the UF as well.&lt;/P&gt;&lt;P&gt;(I'm assuming your UF is sending logs to Indexer directly.)&lt;/P&gt;</description>
      <pubDate>Fri, 08 Apr 2022 08:31:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-after-switching-from-HF-to-UF-MSWindows-2012-IIS-event-no/m-p/593076#M12166</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2022-04-08T08:31:35Z</dc:date>
    </item>
  </channel>
</rss>

