Splunk® Supported Add-ons

Splunk Add-on for Microsoft IIS

Hardware and software requirements for the Splunk Add-on for Microsoft IIS

Splunk admin requirements

To install and configure the Splunk Add-on for Microsoft IIS, you must be member of the admin or sc_admin role.

Microsoft IIS setup requirements

You must enable IIS logging for the Web server from which you want to collect data and use the W3C log file format. Refer to the Microsoft IIS documentation for information about configuring logging in IIS. For more information, search for "Configure Logging in IIS" on the Microsoft documentation.

If you use the IIS Advanced Logging Module and you plan to use the the ms:iis:auto source type for automatic index-time field extraction, do not include the EndRequest-UTC and BeginRequest-UTC fields when you configure the logging fields in the IIS Advanced Logging module. These fields are not W3C-compliant. For more information about configuring fields using the Advanced Logging Module, search for "Advanced Logging for IIS - Custom Logging" in the Microsoft documentation.

Splunk platform requirements

Because this add-on runs on the Splunk platform, all of the system requirements apply for the Splunk software that you use to run this add-on.

  • For Splunk Enterprise system requirements, see System Requirements in the Splunk Enterprise Installation Manual.
  • For Splunk Light system requirements, see System Requirements in the Splunk Light Installation Manual.
  • If you are managing on-premises forwarders to get data into Splunk Cloud, see System Requirements in the Splunk Enterprise Installation Manual, which includes information about forwarders.

For information about installation locations and environments, see Install the Splunk Add-on for Microsoft IIS.

Last modified on 21 July, 2021
Splunk Add-on for Microsoft IIS   Installation and configuration overview for the Splunk Add-on for Microsoft IIS

This documentation applies to the following versions of Splunk® Supported Add-ons: released


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters