Splunk Enterprise Security

How to get IIS events into Enterprise Security App

asonenthal
New Member

Splunkers,

I am trying to get IIS log W3C log events into Enterprise Security App. I made the IIS events an eventtype with tag: web, and made the following field aliases:

c_ip as src
cs_Cookie as cookie
cs_Referer as http_referrer
cs_User_Agent as http_user_agent
cs_bytes as bytes_in
s_ip as dest
cs_method as http_method
cs_uri_stem as uri_path
s_sitename as site
sc_bytes as bytes_out
sc_status as status
cs_username as user

I made the permissions as wide as possible, but after a reboot ESA still does not see the data as for example the ESA HTTP User Agent Analysis remains blank. What am I doing wrong?

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

As mentioned, you need to have these events tagged for web and proxy for ES. You should refer to the documentation for ES's dashboards for how your data should be tagged to appear in these correctly.

http://docs.splunk.com/Documentation/ES/3.2.1/User/MoreNetworkdashboards

http://docs.splunk.com/Documentation/CIM/4.1.0/User/Web

0 Karma

MinaMina
New Member

Hello,
I also need to get IIS logs into Splunk ES app, which add-on did you used ?
Thx,

0 Karma

LukeMurphey
Champion

The web data model was intended for use with proxy log and thus requires two tags: web and proxy.

Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...