Getting Data In

IIS logging change from w3c format to IIS format

cbaiocchetti
New Member

Hello All,

We currently are ingesting IIS logs that are being created in W3C format. We're using a simple folder monitor with the following Inputs.conf syntax:

[monitor://C:\inetpub\logs\LogFiles]
disabled = false
recursive = true
index = iis_staging
sourcetype = iis
ignoreOlderThan = 7d

Now, our web admins want to change IIS logging from W3C to IIS format. I have installed the Splunk Add-on for Microsoft IIS app on our local deployment server, but I am concerned about existing logs in our cloud instance and what may happen to them if I switch the apps from just file monitor to the IIS app. Can the IIS app write to the same index or will I need to create a new index and take other steps to prepare for the new logging format?

Thanks in advance for any advice.

Best,

Chris

Tags (2)
0 Karma
Get Updates on the Splunk Community!

What You Read The Most: Splunk Lantern’s Most Popular Articles!

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...

Index This | What goes away as soon as you talk about it?

May 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this month’s ...