<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Add-on for Microsoft IIS - ms:iis:auto - No Fields Extracted in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Microsoft-IIS-ms-iis-auto-No-Fields-Extracted/m-p/520341#M87961</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It looks like it is already installed on the search heads.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="iamperson347_0-1600437206016.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10888i1341F2193F837325/image-size/medium?v=v2&amp;amp;px=400" role="button" title="iamperson347_0-1600437206016.png" alt="iamperson347_0-1600437206016.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 18 Sep 2020 13:54:42 GMT</pubDate>
    <dc:creator>iamperson347</dc:creator>
    <dc:date>2020-09-18T13:54:42Z</dc:date>
    <item>
      <title>Splunk Add-on for Microsoft IIS - ms:iis:auto - No Fields Extracted</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Microsoft-IIS-ms-iis-auto-No-Fields-Extracted/m-p/520336#M87959</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I've followed the instructions here (&lt;A href="https://docs.splunk.com/Documentation/AddOns/latest/MSIIS/About" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/AddOns/latest/MSIIS/About&lt;/A&gt;) to ingest MS IIS logs into splunk. I have installed the universal forwarder on our test windows server, as well as the IIS Splunkbase app on the windows server and our heavy forwarder. (Our heavy forwarder is configured to forward upstream.)&lt;/P&gt;&lt;P&gt;For inputs on the test windows server, we have this configured:&lt;/P&gt;&lt;P&gt;C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_microsoft-iis\local\inputs.conf&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[monitor://C:\inetpub\logs\LogFiles]
disabled = 0
index = test_index
sourcetype = ms:iis:auto&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Example of the IIS log:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;#Software: Microsoft Internet Information Services 8.5
#Version: 1.0
#Date: 2020-09-18 13:15:43
#Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken
2020-09-18 13:15:43 127.0.0.1 GET / - 80 - 127.0.0.1 Mozilla/5.0+(Windows+NT+6.3;+WOW64;+Trident/7.0;+rv:11.0)+like+Gecko - 304 0 0 171
2020-09-18 13:15:43 127.0.0.1 GET /iis-85.png - 80 - 127.0.0.1 Mozilla/5.0+(Windows+NT+6.3;+WOW64;+Trident/7.0;+rv:11.0)+like+Gecko http://localhost/ 304 0 0 0
2020-09-18 13:15:43 127.0.0.1 GET /favicon.ico - 80 - 127.0.0.1 Mozilla/5.0+(Windows+NT+6.3;+Win64;+x64;+Trident/7.0;+rv:11.0)+like+Gecko - 404 0 2 0&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Data from Splunk Search:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="iamperson347_0-1600436227742.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10887i47B788F8F74160FE/image-size/large?v=v2&amp;amp;px=999" role="button" title="iamperson347_0-1600436227742.png" alt="iamperson347_0-1600436227742.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any idea on why fields aren't being extracted? Not even host is being extracted. Other logs from our windows servers work fine, this is the only app/log type we are currently having trouble with.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Sep 2020 13:43:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Microsoft-IIS-ms-iis-auto-No-Fields-Extracted/m-p/520336#M87959</guid>
      <dc:creator>iamperson347</dc:creator>
      <dc:date>2020-09-18T13:43:23Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Microsoft IIS - ms:iis:auto - No Fields Extracted</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Microsoft-IIS-ms-iis-auto-No-Fields-Extracted/m-p/520338#M87960</link>
      <description>&lt;P&gt;Try installing the IIS add-on on your search head(s).&lt;/P&gt;</description>
      <pubDate>Fri, 18 Sep 2020 13:51:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Microsoft-IIS-ms-iis-auto-No-Fields-Extracted/m-p/520338#M87960</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-09-18T13:51:13Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Microsoft IIS - ms:iis:auto - No Fields Extracted</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Microsoft-IIS-ms-iis-auto-No-Fields-Extracted/m-p/520341#M87961</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It looks like it is already installed on the search heads.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="iamperson347_0-1600437206016.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10888i1341F2193F837325/image-size/medium?v=v2&amp;amp;px=400" role="button" title="iamperson347_0-1600437206016.png" alt="iamperson347_0-1600437206016.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Sep 2020 13:54:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Microsoft-IIS-ms-iis-auto-No-Fields-Extracted/m-p/520341#M87961</guid>
      <dc:creator>iamperson347</dc:creator>
      <dc:date>2020-09-18T13:54:42Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Microsoft IIS - ms:iis:auto - No Fields Extracted</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Microsoft-IIS-ms-iis-auto-No-Fields-Extracted/m-p/520664#M87995</link>
      <description>&lt;P&gt;Issue was with the search itself - not the fields from the app.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Sep 2020 16:39:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Microsoft-IIS-ms-iis-auto-No-Fields-Extracted/m-p/520664#M87995</guid>
      <dc:creator>iamperson347</dc:creator>
      <dc:date>2020-09-21T16:39:37Z</dc:date>
    </item>
  </channel>
</rss>

