Getting Data In

IIS logging change from w3c format to IIS format

cbaiocchetti
New Member

Hello All,

We currently are ingesting IIS logs that are being created in W3C format. We're using a simple folder monitor with the following Inputs.conf syntax:

[monitor://C:\inetpub\logs\LogFiles]
disabled = false
recursive = true
index = iis_staging
sourcetype = iis
ignoreOlderThan = 7d

Now, our web admins want to change IIS logging from W3C to IIS format. I have installed the Splunk Add-on for Microsoft IIS app on our local deployment server, but I am concerned about existing logs in our cloud instance and what may happen to them if I switch the apps from just file monitor to the IIS app. Can the IIS app write to the same index or will I need to create a new index and take other steps to prepare for the new logging format?

Thanks in advance for any advice.

Best,

Chris

Tags (2)
0 Karma
Get Updates on the Splunk Community!

Leveraging Detections from the Splunk Threat Research Team & Cisco Talos

  Now On Demand  Stay ahead of today’s evolving threats with the combined power of the Splunk Threat Research ...

New in Splunk Observability Cloud: Automated Archiving for Unused Metrics

Automated Archival is a new capability within Metrics Management; which is a robust usage & cost optimization ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...