All Apps and Add-ons

Splunk Add-on for Microsoft IIS: error messages - page not found

nathanallmont
New Member

Latest version of the add-on installed on Splunk 6.6.3, any guidance would be appreciated

I've just installed the IIS Add-on and when launching the app i get "404 not found" "Page not found!"

0 Karma

nathanallmont
New Member

Really helpful, Thank you rpille!

0 Karma

rpille_splunk
Splunk Employee
Splunk Employee

That add-on isn't meant to be visible in Splunk Web, so that's why you're seeing that. This is covered in docs here: http://docs.splunk.com/Documentation/AddOns/released/MSIIS/Troubleshoot#Cannot_launch_add-on

To turn visibility off for this add-on:
1. Go to Apps > Manage Apps.
2. Find the row for the IIS add-on and click Edit properties.
3. Under Visible, choose No, then click Save.

0 Karma

nathanallmont
New Member

Thanks for your guidance rpille. How do I view the app if I can't launch it from Splunk Web?

0 Karma

rpille_splunk
Splunk Employee
Splunk Employee

Hi Nathan,

There aren't any dashboards or configuration screens in the add-on itself that you can view.

Instead, install it on your search heads and indexers and then don't worry about it again -- it just needs to be present there to do work behind the scenes for the data that comes in.

To collect the data with this add-on, install the add-on on a forwarder that is installed directly on your Microsoft IIS server, and then follow these directions to configure the input: http://docs.splunk.com/Documentation/AddOns/released/MSIIS/Setupaddon.

If you are just doing a POC and you don't have a distributed Splunk platform deployment, you can just install a full Splunk Enterprise instance directly on the Microsoft IIS server, install the add-on on that, and then do everything right there.

Once you have the data coming in, you can add this add-on's three prebuilt panels to a dashboard to kickstart any visualizations you want to make. The instructions for accessing an add-on's prebuilt panels are here: http://docs.splunk.com/Documentation/AddOns/released/Overview/Prebuiltpanels

0 Karma
Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...