Hi dglass2015
It's difficult to say what the problem might be without any details. In your post you mention Splunk Weblog addon. That addon does not do any data inputs and does not need to be configured at all. It just needs to be installed. The app setup page checks if this has been installed or not.
To troubleshoot, do you get any results for this search query?
tag=web
If you do, verify that the data model has been accelerated.
If not, do you get anything for this query?
index=* (sourcetype=access OR sourcetype=iis)
If not, the sourcetype for the data you have in Splunk is not according to the documentation. You can use sourcetype renaming, reimporting the data under a new sourcetype, or by modifying the eventtype definition.
If you let me know more details I can try and help.
J
... View more