Getting Data In

Search information from IIS logs

tbalouch
Path Finder

Hi Guys,

Do you know of a Splunk App that facilitates searching of IIS logs? Also is there a way I can parse logs to find out which users attempted to login to my IIS servers and if they were successful or not? Is there a custom search I can use?

Tags (2)
0 Karma
1 Solution

lukejadamec
Super Champion

IIS logs are great fun to search, if the search time extractions are configured correctly in splunk. Unfortunately, the configuration often requires manual adjustments. Read this post, it contains pretty much everything you need to know.

http://answers.splunk.com/answers/24986/iis-log-fields-not-parsing

View solution in original post

0 Karma

tbalouch
Path Finder

Thanks this is great!

0 Karma

lukejadamec
Super Champion

IIS logs are great fun to search, if the search time extractions are configured correctly in splunk. Unfortunately, the configuration often requires manual adjustments. Read this post, it contains pretty much everything you need to know.

http://answers.splunk.com/answers/24986/iis-log-fields-not-parsing

0 Karma

tbalouch
Path Finder

Thanks so much!

0 Karma

dart
Splunk Employee
Splunk Employee

Hi,

When you're asking about login to IIS, do you mean logging onto Windows, or logging into a web page/app?

If it's the former, then the Splunk App for Windows includes setup for looking at windows logins, if it's the latter, and you're recording authentication in the IIS logs, then the Splunk Add-on for Weblogs can help you set up field extractions for pulling out the user field, which should get you most of the way to a report on logged in users.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...

Developer Spotlight with Mika Borner

From Hackathon Winner to Enterprise Leader    Mika Borner, CEO and Founder of Datapunctum AG, has been ...

Continue Your Federation Journey: Join Session 3 of the Bootcamp Series

To help practitioners build a stronger foundation, we launched the Data Management & Federation ...