Getting Data In

Splunk For IIS?

khskinsfan
Engager

Is there a Splunk for IIS that can be used on version 4.x?

Thanks.

Tags (2)
1 Solution

jbsplunk
Splunk Employee
Splunk Employee

You should just be able to run a splunk instance on IIS and set up a data input to monitor the directory locally. There is an IIS sourcetype natively built into the product. A good place to start would be here:

http://www.splunk.com/base/Documentation/4.1.6/admin/WhatSplunkCanMonitor

View solution in original post

demodav
Path Finder

Link is no longer available

0 Karma

khskinsfan
Engager

I am looking for mostly the reporting aspect to produce meaningful reports for customer. Like request per month. Request per Client IP. User Agent reports, etc... At the moment I am not profiecient in writing the queries required to produce such charts in splunk. But working on it.

I have splunk looking at offline iis logs at the moment, nothing live.

0 Karma

southeringtonp
Motivator

Arguably a "web analytics" app would be better -- there's probably not that much of interest that specific to IIS over any other web server. I have some very preliminary stuff, and probably so do a lot of other people. But nothing usable enough to share yet.

araitz
Splunk Employee
Splunk Employee

There is definitely a need for an IIS app, or at least an add-on.

southeringtonp
Motivator

What are you looking for in the app - just parsing and field extractions, or more complete logic?

0 Karma

jbsplunk
Splunk Employee
Splunk Employee

You should just be able to run a splunk instance on IIS and set up a data input to monitor the directory locally. There is an IIS sourcetype natively built into the product. A good place to start would be here:

http://www.splunk.com/base/Documentation/4.1.6/admin/WhatSplunkCanMonitor

eantonio
Path Finder

I would like to monitor IIS logs on my remote Web Servers. How to I do that?

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...