Splunk Search

IIS 6.0 logs (W3C Extended) columns names are shifted one position from the data due to "#Fields: "

splun88
Engager

I am indexing W3C Extended IIS logs and have found that Splunk is extracting column headers from the logs, but due to the "#Fields: " text at the beginning of the line introducing the column headings, each piece of data is associated with the wrong column.

It seems that Splunk is considering "#Fields:" as a column header as well, so the date of each log entry is associated with #Fields, the time is associated with date, the cs-method is associated with time, and so on.

Any ideas of how to correct this? I can't seem to find any method to tell IIS to add a CRLF after the "#Fields:" string so that the column headers align properly with their data.

Tags (2)

justinhart
Path Finder

You will need to set up the headers of the columns manually that will be extracted. See this Q/A. Basically, you will set up a manual extraction defined by the sourcetype of the IIS logs that you are indexing. Hope this helps.

Get Updates on the Splunk Community!

There's No Place Like Chrome and the Splunk Platform

Watch On DemandMalware. Risky Extensions. Data Exfiltration. End-users are increasingly reliant on browsers to ...

The Great Resilience Quest: 5th Leaderboard Update

The fifth leaderboard update for The Great Resilience Quest is out >> 🏆 Check out the ...

Devesh Logendran, Splunk, and the Singapore Cyber Conquest

At this year’s Splunk University, I had the privilege of chatting with Devesh Logendran, one of the winners in ...