Getting Data In
Highlighted

custom iis sourcetype - field extractions

Communicator

trying to copy standard IIS field extractions to a new custom sourcetype, however these are not displaying from the indexer cluster. any suggestions? am I missing a transforms in the custom app? looked for any reference of iis in the transforms.conf located in system/default, but could not find any reference.

props.conf (custom app1)
[emeaqaiislogs]
CHARSET=UTF-8
INDEXED
EXTRACTIONS=w3c
MAXTIMESTAMPLOOKAHEAD=32
SHOULDLINEMERGE=false
category=Web
description=W3C Extended log format produced by the Microsoft Internet Information Services (IIS) web server
detect
trailingnulls=auto
disabled=false
pulldown
type=true
TZ=GMT
LINE_BREAKER=([\r\n]+)

props.conf (system/default)
[iis]
CHARSET=UTF-8
INDEXEDEXTRACTIONS=w3c
MAX
TIMESTAMPLOOKAHEAD=32
SHOULD
LINEMERGE=false
category=Web
description=W3C Extended log format produced by the Microsoft Internet Information Services (IIS) web server
detecttrailingnulls=auto
disabled=false
pulldowntype=true
LINE
BREAKER=([\r\n]+)

0 Karma
Highlighted

Re: custom iis sourcetype - field extractions

Motivator

Are the logs coming from a heavy or universal forwarder?

Cheers,
Jacob
0 Karma
Highlighted

Re: custom iis sourcetype - field extractions

Communicator

UFs to a heavy forwarder, but I have applied the props on the HF too.

0 Karma