Splunk Enterprise Security

How to get IIS events into Enterprise Security App

asonenthal
New Member

Splunkers,

I am trying to get IIS log W3C log events into Enterprise Security App. I made the IIS events an eventtype with tag: web, and made the following field aliases:

c_ip as src
cs_Cookie as cookie
cs_Referer as http_referrer
cs_User_Agent as http_user_agent
cs_bytes as bytes_in
s_ip as dest
cs_method as http_method
cs_uri_stem as uri_path
s_sitename as site
sc_bytes as bytes_out
sc_status as status
cs_username as user

I made the permissions as wide as possible, but after a reboot ESA still does not see the data as for example the ESA HTTP User Agent Analysis remains blank. What am I doing wrong?

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

As mentioned, you need to have these events tagged for web and proxy for ES. You should refer to the documentation for ES's dashboards for how your data should be tagged to appear in these correctly.

http://docs.splunk.com/Documentation/ES/3.2.1/User/MoreNetworkdashboards

http://docs.splunk.com/Documentation/CIM/4.1.0/User/Web

0 Karma

MinaMina
New Member

Hello,
I also need to get IIS logs into Splunk ES app, which add-on did you used ?
Thx,

0 Karma

LukeMurphey
Champion

The web data model was intended for use with proxy log and thus requires two tags: web and proxy.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...