<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IIS Logs - Format Question in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/IIS-Logs-Format-Question/m-p/182405#M36573</link>
    <description>&lt;P&gt;Splunk is probably looking for a specific format. Try changing your IIS server to use W3C log format rather than IIS since it is a standard logging format.&lt;/P&gt;</description>
    <pubDate>Thu, 29 May 2014 17:04:17 GMT</pubDate>
    <dc:creator>terridonahue</dc:creator>
    <dc:date>2014-05-29T17:04:17Z</dc:date>
    <item>
      <title>IIS Logs - Format Question</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/IIS-Logs-Format-Question/m-p/182404#M36572</link>
      <description>&lt;P&gt;I have added some IIS logs to Splunk via the "Files and Directories" input.  While I can query the raw data it does not appear that Splunk is recognizing the format of these logs.  For example when I query "source="\\xxxxxxxxx\IIS Logs*"" I receive the following results:&lt;/P&gt;

&lt;P&gt;119.63.193.195, -, 5/21/2014, 23:59:53, W3SVC3, xxxxxxxxx , xx.xx.xx.xx, 187, 144, 2800, 200, 64, GET, /, -,&lt;BR /&gt;
date_hour = 23 date_mday = 21 date_minute = 59 date_month = may date_second = 53 date_wday = wednesday date_year = 2014 date_zone = local eventtype = wineventlog-index eventtype = winevents host = xxxxxxx index = main linecount = 1 punct = ...,&lt;EM&gt;-,&lt;/EM&gt;//,&lt;EM&gt;::,&lt;/EM&gt;,&lt;EM&gt;,&lt;/EM&gt;...,&lt;EM&gt;,&lt;/EM&gt;,&lt;EM&gt;,&lt;/EM&gt;,&lt;EM&gt;,&lt;/EM&gt;,&lt;EM&gt;/,&lt;/EM&gt;-, source = \xxxxxxxxx\IIS Logs\u_in14052123.log sourcetype = u_in-too_small splunk_server = xxxxxxxxx timeendpos = 38 timestartpos = 19&lt;/P&gt;

&lt;P&gt;The first part of the result "119.63.193.195" is the client IP that accessed this website.  My issue is that splunk is not recognizing this field as the clientip.&lt;/P&gt;

&lt;P&gt;My logs are in IIS format.&lt;/P&gt;

&lt;P&gt;What am I doing wrong?&lt;/P&gt;

&lt;P&gt;Additionally, in the above results, what is "punct = ...,&lt;EM&gt;-,&lt;/EM&gt;//,&lt;EM&gt;::,&lt;/EM&gt;,&lt;EM&gt;,&lt;/EM&gt;...,&lt;EM&gt;,&lt;/EM&gt;,&lt;EM&gt;,&lt;/EM&gt;,&lt;EM&gt;,&lt;/EM&gt;,&lt;EM&gt;/,&lt;/EM&gt;-,"?&lt;/P&gt;

&lt;P&gt;Thank you for your time.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 16:45:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/IIS-Logs-Format-Question/m-p/182404#M36572</guid>
      <dc:creator>JoshuaThompson</dc:creator>
      <dc:date>2020-09-28T16:45:09Z</dc:date>
    </item>
    <item>
      <title>Re: IIS Logs - Format Question</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/IIS-Logs-Format-Question/m-p/182405#M36573</link>
      <description>&lt;P&gt;Splunk is probably looking for a specific format. Try changing your IIS server to use W3C log format rather than IIS since it is a standard logging format.&lt;/P&gt;</description>
      <pubDate>Thu, 29 May 2014 17:04:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/IIS-Logs-Format-Question/m-p/182405#M36573</guid>
      <dc:creator>terridonahue</dc:creator>
      <dc:date>2014-05-29T17:04:17Z</dc:date>
    </item>
    <item>
      <title>Re: IIS Logs - Format Question</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/IIS-Logs-Format-Question/m-p/182406#M36574</link>
      <description>&lt;P&gt;Is there a way that I can tell Splunk the format of my data?  Changing the format to W3C helps me going forward but it does not help for the data that has already been indexed.&lt;/P&gt;</description>
      <pubDate>Thu, 29 May 2014 18:32:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/IIS-Logs-Format-Question/m-p/182406#M36574</guid>
      <dc:creator>JoshuaThompson</dc:creator>
      <dc:date>2014-05-29T18:32:17Z</dc:date>
    </item>
    <item>
      <title>Re: IIS Logs - Format Question</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/IIS-Logs-Format-Question/m-p/182407#M36575</link>
      <description>&lt;P&gt;I am looking to see if there is. I am sure it can be designated on the conf file but need to determine what goes there. Also punct is simply the entire line item with everything but punctuation removed. You can use it to find like items. For more info: &lt;A href="http://docs.splunk.com/Splexicon:Punct"&gt;http://docs.splunk.com/Splexicon:Punct&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 29 May 2014 20:59:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/IIS-Logs-Format-Question/m-p/182407#M36575</guid>
      <dc:creator>terridonahue</dc:creator>
      <dc:date>2014-05-29T20:59:07Z</dc:date>
    </item>
    <item>
      <title>Re: IIS Logs - Format Question</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/IIS-Logs-Format-Question/m-p/182408#M36576</link>
      <description>&lt;P&gt;Terridonahue - If you find the answer please let me know.  I will do likewise.    Thank you for the information on "punct". I do appreciate it.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jun 2014 19:33:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/IIS-Logs-Format-Question/m-p/182408#M36576</guid>
      <dc:creator>JoshuaThompson</dc:creator>
      <dc:date>2014-06-02T19:33:47Z</dc:date>
    </item>
  </channel>
</rss>

