Splunk Search

IIS logs

cybermonk3y5
New Member

I am learning Splunk and playing with different log types. So far I have exported the CSV files and played around. I have some IIS logs (in txt format) that I want to mess with. Is there a way to import these to Splunk enterprise? I want to import the text files I have and play with logs create some searches and do more. Any help is appreciated. Thank you.

Labels (5)
0 Karma

General_Talos
Path Finder

If your IIS logs are getting stored on a Specific location/path on a system you can try installing a UF and perform "file and folder monitoring to that location/path.

https://docs.splunk.com/Documentation/Splunk/8.1.1/Data/Monitorfilesanddirectorieswithinputs.conf

https://docs.splunk.com/Documentation/AddOns/released/MSIIS/Setupaddon

 

 

0 Karma
Get Updates on the Splunk Community!

Detecting Brute Force Account Takeover Fraud with Splunk

This article is the second in a three-part series exploring advanced fraud detection techniques using Splunk. ...

Buttercup Games: Further Dashboarding Techniques (Part 9)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Buttercup Games: Further Dashboarding Techniques (Part 8)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...