Splunk® Supported Add-ons

Splunk Add-on for Microsoft IIS

Acrobat logo Download manual as PDF


Acrobat logo Download topic as PDF

Release notes for the Splunk Add-on for Microsoft IIS

Version 1.3.0 of the Splunk Add-on for Microsoft IIS was released on January 30, 2024.

Compatibility

This release is compatible with the following software, CIM versions, and platforms.

Splunk platform versions 9.0.x, 9.1.x
CIM 5.3.1
Platforms Platform-independent
Vendor Products Microsoft IIS 7.0, Microsoft IIS 7.5, Microsoft IIS 8.0, Microsoft IIS 8.5, Microsoft IIS 10.0

The field alias functionality is compatible with the current version of this add-on. The current version of this add-on does not support older field alias configurations.

For more information about the field alias configuration change, refer to the Splunk Enterprise Release Notes.

New Features

  • Added support for a new input powershell://IISModules to collect a list of global modules installed in the IIS Servers. See Configure Powershell inputs for more information.

Fixed issues

Version 1.3.0 of the Splunk Add-on for Microsoft IIS has the following fixed issues:


If no issues appear, no issues were currently fixed for this release.

Known issues

This version of the Splunk Add-on for Microsoft IIS contains the following known issues.

If no issues appear, no issues have yet been reported.


Date filed Issue number Description
2020-09-24 ADDON-29718, ADDON-29686 Invalid scheme in URL field for 'ms:iis:auto', 'ms:iis:default', 'ms:iis:default:85' sourcetypes

Workaround:
Steps to resolve issue for search-time sourcetypes ( ms:iis:default, ms:iis:default:85 ):

1. Enable the HTTPS Server Variable with the field name as "https". ( The steps followed for ms:iis:splunk sourcetype. )
2. Update the Field transformation of the respective sourcetype "auto_kv_for_iis_default" (for ms:iis:default) and "auto_kv_for_iis_default_85" (for ms:iis:default:85) with the updated "Field" string from IIS log files.
3. The url field will have the correct scheme for the URL.

Steps to resolve issue for index-time sourcetype ( ms:iis:auto ):
1. Enable the HTTPS Server Variable with the field name as "https". ( The steps followed for ms:iis:splunk sourcetype. )
2. Rollover the log file either from IIS manually or wait for IIS to rollover the logfile for writing the logs.
3. The url field will have the correct scheme for the url.

Third-party software attributions

Version 1.3.0 of the Splunk Add-on for Microsoft IIS does not incorporate any third-party software or libraries.

Last modified on 07 February, 2024
PREVIOUS
Source types for the Splunk Add-on for Microsoft IIS
  NEXT
Release history for the Splunk Add-on for Microsoft IIS

This documentation applies to the following versions of Splunk® Supported Add-ons: released


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters