Getting Data In

Why are IIS logs not reliably getting in?

paulgo
Explorer

I am sending IIS logs to SplunkCloud.  My inputs.conf looks like this:

 

[monitor://C:\inetpub\logs\LogFiles\W3SVC1]
ignoreOlderThan = 7d
sourcetype = web_log
initCrcLength = 400


[monitor://C:\inetpub\wwwroot\merge\requestlogs\...\*.csv]
ignoreOlderThan = 7d
sourcetype = csv_webrequest
crcSalt = <string>
recursive = true
initCrcLength = 400

 

It will work fine for a while, with SplunkCloud getting our data every second reliably as logs update.  

The next day it will stop working, with log ingest slowing to a trickle: a few lines every few minutes. Restarting the forwarder occasionally works.  Making a different change can work (changing the initCrcLength, adding or removing crcSalt, adding or removing alwaysOpenFile) but nothing works for more than a day or so.  

Does anyone have any suggestions?

Thanks in advance.

Labels (1)
0 Karma
1 Solution

shivanshu1593
Builder

What are the internal logs saying about the server that is sending logs to SplunkCloud? Any warnings or error messages that you can share for further help?

index=_internal host=<host_sending_logs> log_level IN ("ERROR", "WARN")




Thank you,
Shiv
###If you found the answer helpful, kindly consider upvoting/accepting it as the answer as it helps other Splunkers find the solutions to similar issues###

View solution in original post

isoutamo
SplunkTrust
SplunkTrust

Hi

have you try this app https://splunkbase.splunk.com/app/3185 to collect those or are you using your own inputs.conf without any other definitions?

I propose to use that TA on all relevant places (see installation & configuration instructions).

r. Ismo

0 Karma

shivanshu1593
Builder

What are the internal logs saying about the server that is sending logs to SplunkCloud? Any warnings or error messages that you can share for further help?

index=_internal host=<host_sending_logs> log_level IN ("ERROR", "WARN")




Thank you,
Shiv
###If you found the answer helpful, kindly consider upvoting/accepting it as the answer as it helps other Splunkers find the solutions to similar issues###

paulgo
Explorer

This worked.  Thanks!

0 Karma
Get Updates on the Splunk Community!

Developer Spotlight with Brett Adams

In our third Spotlight feature, we're excited to shine a light on Brett—a Splunk consultant, innovative ...

Index This | What can you do to make 55,555 equal 500?

April 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Say goodbye to manually analyzing phishing and malware threats with Splunk Attack ...

In today’s evolving threat landscape, we understand you’re constantly bombarded with phishing and malware ...