Hello,
I am using Splunk enterprise and splunk enterprise security. I have windows IIS TA configured as well.How to find the IIS events in splunk search in order to create alert.Kindly help
@Arpmjdr
Are you using "Splunk Add-on for Microsoft IIS" (http://splunkbase.splunk.com/app/3185)? If yes then check events by executing below search?
1) sourcetype="ms:iis:auto"
2) sourcetype="ms:iis:default"