Getting Data In

Splunk For IIS?

khskinsfan
Engager

Is there a Splunk for IIS that can be used on version 4.x?

Thanks.

Tags (2)
1 Solution

jbsplunk
Splunk Employee
Splunk Employee

You should just be able to run a splunk instance on IIS and set up a data input to monitor the directory locally. There is an IIS sourcetype natively built into the product. A good place to start would be here:

http://www.splunk.com/base/Documentation/4.1.6/admin/WhatSplunkCanMonitor

View solution in original post

demodav
Path Finder

Link is no longer available

0 Karma

khskinsfan
Engager

I am looking for mostly the reporting aspect to produce meaningful reports for customer. Like request per month. Request per Client IP. User Agent reports, etc... At the moment I am not profiecient in writing the queries required to produce such charts in splunk. But working on it.

I have splunk looking at offline iis logs at the moment, nothing live.

0 Karma

southeringtonp
Motivator

Arguably a "web analytics" app would be better -- there's probably not that much of interest that specific to IIS over any other web server. I have some very preliminary stuff, and probably so do a lot of other people. But nothing usable enough to share yet.

araitz
Splunk Employee
Splunk Employee

There is definitely a need for an IIS app, or at least an add-on.

southeringtonp
Motivator

What are you looking for in the app - just parsing and field extractions, or more complete logic?

0 Karma

jbsplunk
Splunk Employee
Splunk Employee

You should just be able to run a splunk instance on IIS and set up a data input to monitor the directory locally. There is an IIS sourcetype natively built into the product. A good place to start would be here:

http://www.splunk.com/base/Documentation/4.1.6/admin/WhatSplunkCanMonitor

eantonio
Path Finder

I would like to monitor IIS logs on my remote Web Servers. How to I do that?

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...