<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk App for Web Intelligence: what should column names be for IIS log data? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-App-for-Web-Intelligence-what-should-column-names-be-for/m-p/96405#M20104</link>
    <description>&lt;P&gt;Figured it out. For anyone else who wants a fix for this:&lt;/P&gt;

&lt;P&gt;1) navigate to Manager » Fields » Field aliases&lt;/P&gt;

&lt;P&gt;2) Click on each alias, and add a new alias&lt;/P&gt;</description>
    <pubDate>Sat, 22 Oct 2011 00:17:09 GMT</pubDate>
    <dc:creator>stjack99</dc:creator>
    <dc:date>2011-10-22T00:17:09Z</dc:date>
    <item>
      <title>Splunk App for Web Intelligence: what should column names be for IIS log data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-App-for-Web-Intelligence-what-should-column-names-be-for/m-p/96404#M20103</link>
      <description>&lt;P&gt;I'm having a problem getting web intel app showing any results. I've investigated a bit, and think the problem is the column names I used.&lt;/P&gt;

&lt;P&gt;This is what I currently have set:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://community.splunk.com/from%20transforms.conf" target="_blank"&gt;iislogs&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;FIELDS = "date", "time", "s_siteName", "s_computername", "dest_ip", "http_method", "uri_stem", "uri_query", "dest_port", "user", "src_ip", "http_user_agent", "http_cookie", "http_referrer", "dest_host", "http_response", "http_sub_response", "sc_win32Status", "bytes_out", "bytes_in", "duration"&lt;/P&gt;

&lt;P&gt;DELIMS = " "&lt;/P&gt;

&lt;P&gt;What column names does web intel expect me to have?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 10:00:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-App-for-Web-Intelligence-what-should-column-names-be-for/m-p/96404#M20103</guid>
      <dc:creator>stjack99</dc:creator>
      <dc:date>2020-09-28T10:00:42Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Web Intelligence: what should column names be for IIS log data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-App-for-Web-Intelligence-what-should-column-names-be-for/m-p/96405#M20104</link>
      <description>&lt;P&gt;Figured it out. For anyone else who wants a fix for this:&lt;/P&gt;

&lt;P&gt;1) navigate to Manager » Fields » Field aliases&lt;/P&gt;

&lt;P&gt;2) Click on each alias, and add a new alias&lt;/P&gt;</description>
      <pubDate>Sat, 22 Oct 2011 00:17:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-App-for-Web-Intelligence-what-should-column-names-be-for/m-p/96405#M20104</guid>
      <dc:creator>stjack99</dc:creator>
      <dc:date>2011-10-22T00:17:09Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Web Intelligence: what should column names be for IIS log data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-App-for-Web-Intelligence-what-should-column-names-be-for/m-p/96406#M20105</link>
      <description>&lt;P&gt;What aliases did you add?&lt;/P&gt;</description>
      <pubDate>Tue, 20 Dec 2011 16:52:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-App-for-Web-Intelligence-what-should-column-names-be-for/m-p/96406#M20105</guid>
      <dc:creator>CraigF</dc:creator>
      <dc:date>2011-12-20T16:52:04Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Web Intelligence: what should column names be for IIS log data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-App-for-Web-Intelligence-what-should-column-names-be-for/m-p/96407#M20106</link>
      <description>&lt;P&gt;Here is a list of field aliases that may be needed, taken from [access-extractions] in default/transforms.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[access-extractions]
# matches access-common or access-combined apache logging formats
# Extracts: clientip, clientport, ident, user, req_time, method, uri, root, file, uri_domain, uri_query, version, status, bytes, referer_url, referer_domain, referer_proto, useragent, cookie, other (remaining chars)  
# Note: referer is misspelled in purpose because that is the "official" spelling for "HTTP referer" 
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 13 Dec 2012 15:21:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-App-for-Web-Intelligence-what-should-column-names-be-for/m-p/96407#M20106</guid>
      <dc:creator>MartinHarper</dc:creator>
      <dc:date>2012-12-13T15:21:37Z</dc:date>
    </item>
  </channel>
</rss>

