Reporting

IIS Logs are not showing up in reports for Web Intelligence

Brian_Osburn
Builder

I currently have the Web Intelligence application set up to parse and generate reports off of my Apache logs. Works great, and the reports are very useful.

However, I'm attempting to add some IIS logs to the reports and I'm running into issues.

I modified the setup to include the sourcetypes that the IIS logs are stored under. I re-ran the backfill script for the last 24 hours, and everything seemed fine.

I then re-ran the sourcenames saved search to populate the lookup csv.

First issue:

The IIS logs get rotated. In the sourcenames.csv, can I use wildcards for the source?

Second issue:

The backfill script put everything in the summary indexes with the sourcename == source. So, when it runs the searches against the summary data, it's using the sourcename that I set in the sourcenames.csv and it's not finding anything.

Did I do something wrong?

1 Solution

araitz
Splunk Employee
Splunk Employee

Unfortunately, wildcards don't work in lookups such as sourcenames.csv without some gymnastics. We are planning on improving the workflow for setting up the lookup in question.

Regarding the second issue, I'm not 100% clear on what is happening. The summary index data has source=foo123*. What are the searches looking for?

View solution in original post

0 Karma

araitz
Splunk Employee
Splunk Employee

Unfortunately, wildcards don't work in lookups such as sourcenames.csv without some gymnastics. We are planning on improving the workflow for setting up the lookup in question.

Regarding the second issue, I'm not 100% clear on what is happening. The summary index data has source=foo123*. What are the searches looking for?

0 Karma

araitz
Splunk Employee
Splunk Employee

This is something we intend to address in a forthcoming release of the web intelligence app.

0 Karma

gerald_huddlest
Path Finder

with regard to the IIS logs rotating, was there any further advise on this?

0 Karma

Brian_Osburn
Builder

Hrrm.. So I'll pretty much have to go in and edit the sourcenames.csv every day because the files rotate?

With regards to the second issue:
From what I understand, the searches use the sourcenames.csv to get whatever name we assign to it that source (for example, www.websitename.com). It then uses that to search the WI* summary indexes for sourcename=www.websitename.com. BUT, in the summary indexes, the sourcename has been set to the actual log location (aka the first column in the sourcenames.csv).

Did that make it clearer?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Take Action Automatically on Splunk Alerts with Red Hat Ansible Automation Platform

 Are you ready to revolutionize your IT operations? As digital transformation accelerates, the demand for ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...