Splunk IT Service Intelligence

splunk app for web analytics : sourcetype "ms:iis:auto" configuration instead of "iis"

splunkselva
New Member

Hi ,

Currently, all our webserver (iis server) log events are configured with sourcetype "ms:iis:auto" but default splunk web analytics app inbuilt sourcetype is "iis" . I have followed the app documentation but data is not fetching out while selecting generate users sessions option.

modified eventtype configurations:
web-traffic sourcetype="aws:cloudfront:accesslogs" OR sourcetype="apache:access" OR sourcetype="iis" OR sourcetype="ms:iis:auto" OR sourcetype="access_combined" OR sourcetype="access_common" OR sourcetype="access_combined_wcookie"

Is there any other configuration steps required for Splunk App for Web Analytics app work with "ms:iis:auto" sourcetype ?

Regards,
Selva

0 Karma
.conf21 CFS Extended through 5/20!

Don't miss your chance
to share your Splunk
wisdom in-person or
virtually at .conf21!

Call for Speakers has
been extended through
Thursday, 5/20!