Getting Data In

Sourcetype confusion over IIS logs- Help to find a cogent Spec and Select

kmower
Communicator

I have been doing testing and planning out my Splunk deployment. I have set up a Universal Forwarder on one of our pre-Production servers and am bringing in IIS logs in the iis sourcetype.

However, after having done some Splunk training - which seems to be primarily Apache focused (nothing wrong with that, I love Apache but my org is borg ... uh, Microsoft that is). Anyway, I am wondering about the Splunk Add-On for Microsoft IIS - app 3185 on splunkbase - and if there is some coverage of the built-in iis sourcetype and the Add-On for IIS ... I have gone through the forum etc. but I can't seem to find a cogent Spec and Select. Is there one that I am just not finding (betting there is somewhere)? Thanks.

Labels (1)
Tags (2)
0 Karma
1 Solution

FrankVl
Ultra Champion

Haven't thoroughly investigated, but I think the built in sourcetype mostly just applies the indexed w3c extractions, while the iis add-on also provides mapping to CIM datamodel(s) with additional extractions/aliases, eventtyping and tagging.

View solution in original post

FrankVl
Ultra Champion

Haven't thoroughly investigated, but I think the built in sourcetype mostly just applies the indexed w3c extractions, while the iis add-on also provides mapping to CIM datamodel(s) with additional extractions/aliases, eventtyping and tagging.

kmower
Communicator

Hi Frank, Thanks for that. Yes, that is kind of my suspicion too. One thing with Splunk is that there is a lot of Suspicion around these things and not really enough hard data. I see this as a hurdle for uptake in the market, even though Splunk and its share price have been going through the roof. It's not a criticism, but a side effect of fast growth - their information is sparse, patchy and non-definitive. It would be good to know why they rolled out an 'Add-On' vis a vis the native sourcetype. Sourcetypes are a main point (perhaps the main point) of definition for Splunk data, and I think they really need a lot more documentation love than they are getting at present. Thanks.

0 Karma

adonio
Ultra Champion

what is the question?

0 Karma

kmower
Communicator

The question is about sourcetype for IIS logs. What are the advantages of using the Splunk Add-On for Microsoft IIS and its sourcetype of ms:iis:auto (for example) as compared with the inbuilt Splunk sourcetype of iis?

shocko
Contributor

I have essentially asked the same thing over here. Did you ever get an answer? 

0 Karma
Get Updates on the Splunk Community!

Detecting Brute Force Account Takeover Fraud with Splunk

This article is the second in a three-part series exploring advanced fraud detection techniques using Splunk. ...

Buttercup Games: Further Dashboarding Techniques (Part 9)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Buttercup Games: Further Dashboarding Techniques (Part 8)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...