Splunk Search

Not creating iis fields (time-taken) with splunk 6.1 and iis 7 w3c logs

rdstafford
New Member

Looking at documents it appears that IIS w3c logs should auto create all the fields in the header. Am I wrong about that?

If not how do i make it so all the fields are available to be easily searched. The end goal i have is graphing and alerting when certain calls take longer than 3 seconds.

Tags (2)
0 Karma

rdstafford
New Member

Nevermind, it looks like i can search on the fields no problem, it was just not showing up in the events window.

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...