Splunk Search

I didn't use INDEXED_EXTRACTIONS, but why are fields for my IIS logs still getting extracted properly in Splunk 6.2.1?

rsathish47
Contributor

Hi all,

I found blogs on IIS logs and Spunk 6. I didn't use the INDEXED_EXTRACTIONS, but why are fields still getting extracted properly in Splunk 6.2.1? I just want to know about the internal functionality.

http://blogs.splunk.com/2013/10/18/iis-logs-and-splunk-6/

Thanks
Sathish Rangan

0 Karma
1 Solution

jeffland
SplunkTrust
SplunkTrust

If you don't specifically set a sourcetype or any other settings when adding the input, I'd say splunk was smart enough to notice that this is IIS data and decided to use the header data. After all, it is a pretty distinguishable type of log.

View solution in original post

jeffland
SplunkTrust
SplunkTrust

If you don't specifically set a sourcetype or any other settings when adding the input, I'd say splunk was smart enough to notice that this is IIS data and decided to use the header data. After all, it is a pretty distinguishable type of log.

rsathish47
Contributor

Thank you Jeffland.
Is their way to check all per defined header detail in splunk?

0 Karma

rsathish47
Contributor
0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...