Getting Data In

Why are IIS logs not reliably getting in?

paulgo
Explorer

I am sending IIS logs to SplunkCloud.  My inputs.conf looks like this:

 

[monitor://C:\inetpub\logs\LogFiles\W3SVC1]
ignoreOlderThan = 7d
sourcetype = web_log
initCrcLength = 400


[monitor://C:\inetpub\wwwroot\merge\requestlogs\...\*.csv]
ignoreOlderThan = 7d
sourcetype = csv_webrequest
crcSalt = <string>
recursive = true
initCrcLength = 400

 

It will work fine for a while, with SplunkCloud getting our data every second reliably as logs update.  

The next day it will stop working, with log ingest slowing to a trickle: a few lines every few minutes. Restarting the forwarder occasionally works.  Making a different change can work (changing the initCrcLength, adding or removing crcSalt, adding or removing alwaysOpenFile) but nothing works for more than a day or so.  

Does anyone have any suggestions?

Thanks in advance.

Labels (1)
0 Karma
1 Solution

shivanshu1593
Builder

What are the internal logs saying about the server that is sending logs to SplunkCloud? Any warnings or error messages that you can share for further help?

index=_internal host=<host_sending_logs> log_level IN ("ERROR", "WARN")




Thank you,
Shiv
###If you found the answer helpful, kindly consider upvoting/accepting it as the answer as it helps other Splunkers find the solutions to similar issues###

View solution in original post

isoutamo
SplunkTrust
SplunkTrust

Hi

have you try this app https://splunkbase.splunk.com/app/3185 to collect those or are you using your own inputs.conf without any other definitions?

I propose to use that TA on all relevant places (see installation & configuration instructions).

r. Ismo

0 Karma

shivanshu1593
Builder

What are the internal logs saying about the server that is sending logs to SplunkCloud? Any warnings or error messages that you can share for further help?

index=_internal host=<host_sending_logs> log_level IN ("ERROR", "WARN")




Thank you,
Shiv
###If you found the answer helpful, kindly consider upvoting/accepting it as the answer as it helps other Splunkers find the solutions to similar issues###

paulgo
Explorer

This worked.  Thanks!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...