Splunk Search

IIS 6.0 logs (W3C Extended) columns names are shifted one position from the data due to "#Fields: "

splun88
Engager

I am indexing W3C Extended IIS logs and have found that Splunk is extracting column headers from the logs, but due to the "#Fields: " text at the beginning of the line introducing the column headings, each piece of data is associated with the wrong column.

It seems that Splunk is considering "#Fields:" as a column header as well, so the date of each log entry is associated with #Fields, the time is associated with date, the cs-method is associated with time, and so on.

Any ideas of how to correct this? I can't seem to find any method to tell IIS to add a CRLF after the "#Fields:" string so that the column headers align properly with their data.

Tags (2)

justinhart
Path Finder

You will need to set up the headers of the columns manually that will be extracted. See this Q/A. Basically, you will set up a manual extraction defined by the sourcetype of the IIS logs that you are indexing. Hope this helps.

Get Updates on the Splunk Community!

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

  Ready to master Kubernetes and cloud monitoring like the pros?Join Splunk’s Growth Engineering team for an ...

Wrapping Up Cybersecurity Awareness Month

October might be wrapping up, but for Splunk Education, cybersecurity awareness never goes out of season. ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...