Getting Data In

Why is Hunk not picking up the iis sourcetype I configured in props.conf?

jwalzerpitt
Influencer

I created a new virtual index to search against IIS logs (I have an HDFS directory that holds 11 individual logs all formatted for WC3). I selected 'Explore Data', selected the first file, and walked through the steps, selecting 'iis' as the sourcetype and I could see it parsed the fields correctly. Finished Explore Data and the following config was added to my props.conf file:

[source::/LogCentral/IIS/EWI/2015-12-02/EWI-ZWEB-06A_12_02_2015/Default Web Site_151202.log]
sourcetype = iis

I then went in and edited the props.conf file and added the other 10 files and then rebooted the splunk service. I then logged in and ran a search and the events are not being parsed with the iis fields.

Any ideas?

Thx

0 Karma

burwell
SplunkTrust
SplunkTrust

Did you try adding the priority line in that stanza?

0 Karma

burwell
SplunkTrust
SplunkTrust

Could the space in the file name 'Default Web Site_151202.log' be possibly causing a problem?

jwalzerpitt
Influencer

Renamed the file to 'Default_Web_Site_151202.log' and still having the same issue.

Under the generic 'Selected Fields' listing, it says, '71 more fields', but clicking that link only shows me 28 additional fields.

Thx

0 Karma

jwalzerpitt
Influencer

Added priority line and still no iis WC3 fields being extracted:

[source::/LogCentral/IIS/EWI/2015-12-02/EWI-ZWEB-06A_12_02_2015/Default Web Site_151202.log]
sourcetype = iis
priority = 10

Thx

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...