Getting Data In

How do you check where an index is being sent to on an IIS Box ?

itrimble1
Path Finder

We have this on /etc/system/local for testing

Inputs.conf file

[default]

host = server name goes here

[monitor://C:\inetpub\logs\LogFiles\W3SVC1]
sourcetype = ms:iis:default
index = ms_iis
Tags (2)
0 Karma

woodcock
Esteemed Legend

Try these:

$SPLUNK_HOME/bin/splunk btool inputs list --debug
$SPLUNK_HOME/bin/splunk btool props list --debug
0 Karma

anthonymelita
Contributor

You have that in the $SPLUNK_HOME/etcsystem/local, but if you chose to index IIS logs during the MSI install process then it will probably be in a different app under $SPLUNK_HOME/etc/apps

0 Karma

lakshman239
Influencer

per the above, your sourcetype = ms:iis:default logs goes to index=ms_iis

you can search for index=ms_iss sourcetype=ms* to check all sourcetypes related to IIS logs.

0 Karma

itrimble1
Path Finder

I meant from the IIS Box. Which logs on the IIS box would tell me that it's going to the ms_iis index.

I am trying to troubleshoot, why they keep ending up in the catchall main index.

0 Karma

somesoni2
Revered Legend

Run btool on the machine to see what index is actually applied. Other than then, you can look at metrics.log to see which index that sourcetype is going to.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...

Index This | How many sevens are there between 1 and 100?

August 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...