Getting Data In

Why are IIS logs not reliably getting in?

paulgo
Explorer

I am sending IIS logs to SplunkCloud.  My inputs.conf looks like this:

 

[monitor://C:\inetpub\logs\LogFiles\W3SVC1]
ignoreOlderThan = 7d
sourcetype = web_log
initCrcLength = 400


[monitor://C:\inetpub\wwwroot\merge\requestlogs\...\*.csv]
ignoreOlderThan = 7d
sourcetype = csv_webrequest
crcSalt = <string>
recursive = true
initCrcLength = 400

 

It will work fine for a while, with SplunkCloud getting our data every second reliably as logs update.  

The next day it will stop working, with log ingest slowing to a trickle: a few lines every few minutes. Restarting the forwarder occasionally works.  Making a different change can work (changing the initCrcLength, adding or removing crcSalt, adding or removing alwaysOpenFile) but nothing works for more than a day or so.  

Does anyone have any suggestions?

Thanks in advance.

Labels (1)
0 Karma
1 Solution

shivanshu1593
Builder

What are the internal logs saying about the server that is sending logs to SplunkCloud? Any warnings or error messages that you can share for further help?

index=_internal host=<host_sending_logs> log_level IN ("ERROR", "WARN")




Thank you,
Shiv
###If you found the answer helpful, kindly consider upvoting/accepting it as the answer as it helps other Splunkers find the solutions to similar issues###

View solution in original post

isoutamo
SplunkTrust
SplunkTrust

Hi

have you try this app https://splunkbase.splunk.com/app/3185 to collect those or are you using your own inputs.conf without any other definitions?

I propose to use that TA on all relevant places (see installation & configuration instructions).

r. Ismo

0 Karma

shivanshu1593
Builder

What are the internal logs saying about the server that is sending logs to SplunkCloud? Any warnings or error messages that you can share for further help?

index=_internal host=<host_sending_logs> log_level IN ("ERROR", "WARN")




Thank you,
Shiv
###If you found the answer helpful, kindly consider upvoting/accepting it as the answer as it helps other Splunkers find the solutions to similar issues###

paulgo
Explorer

This worked.  Thanks!

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud's AI Assistant in Action Series: Auditing Compliance and ...

This is the third post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

What You Read The Most: Splunk Lantern’s Most Popular Articles!

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...