Getting Data In

Splunk App for Web Intelligence: what should column names be for IIS log data?

stjack99
Explorer

I'm having a problem getting web intel app showing any results. I've investigated a bit, and think the problem is the column names I used.

This is what I currently have set:

iislogs

FIELDS = "date", "time", "s_siteName", "s_computername", "dest_ip", "http_method", "uri_stem", "uri_query", "dest_port", "user", "src_ip", "http_user_agent", "http_cookie", "http_referrer", "dest_host", "http_response", "http_sub_response", "sc_win32Status", "bytes_out", "bytes_in", "duration"

DELIMS = " "

What column names does web intel expect me to have?

0 Karma
1 Solution

stjack99
Explorer

Figured it out. For anyone else who wants a fix for this:

1) navigate to Manager » Fields » Field aliases

2) Click on each alias, and add a new alias

View solution in original post

MartinHarper
Path Finder

Here is a list of field aliases that may be needed, taken from [access-extractions] in default/transforms.conf

[access-extractions]
# matches access-common or access-combined apache logging formats
# Extracts: clientip, clientport, ident, user, req_time, method, uri, root, file, uri_domain, uri_query, version, status, bytes, referer_url, referer_domain, referer_proto, useragent, cookie, other (remaining chars)  
# Note: referer is misspelled in purpose because that is the "official" spelling for "HTTP referer" 
0 Karma

stjack99
Explorer

Figured it out. For anyone else who wants a fix for this:

1) navigate to Manager » Fields » Field aliases

2) Click on each alias, and add a new alias

CraigF
Explorer

What aliases did you add?

Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...