Splunk® Supported Add-ons

Splunk Add-on for Microsoft IIS

Acrobat logo Download manual as PDF


Acrobat logo Download topic as PDF

Release history for the Splunk Add-on for Microsoft IIS

Latest release

The latest version of the Splunk Add-on for Microsoft IIS is version 1.2.0. See Release notes for the Splunk Add-on for Microsoft IIS for the release notes of this latest version.

Release notes for the Splunk Add-on for Microsoft IIS Version 1.0.0

Version 1.0.0 of the Splunk Add-on for Microsoft IIS was released on June 8, 2016.

Compatibility

This release is compatible with the following software, CIM versions, and platforms.

Splunk platform versions 6.3.X and later
CIM 4.4 and later
Platforms Platform-independent
Vendor Products Microsoft IIS 7.0 and later

Features

Version 1.0.0 is the first release of the Splunk Add-on for Microsoft IIS, which provides inputs and CIM normalization for Microsoft IIS W3C-standard log files. This release ships with the following prebuilt panels that you can add to your dashboard:

  • Microsoft IIS - Actions by Dest IP
  • Microsoft IIS - Actions by Src IP
  • Microsoft IIS - Actions by HTTP Method

Known issues

This version of the Splunk Add-on for Microsoft IIS contains the following known issues.


Date filed Issue number Description
2020-08-19 ADDON-28852 File descriptor lines ingested into Splunk when using ms:iis:default sourcetype
2019-01-17 ADDON-20997, ADDON-21142 FIELDALIAS is incorrect for host field

Workaround:
Added:

[ms:iis:auto] FIELDALIAS-s_computername = host as s_computername

2016-05-20 ADDON-9580 EndRequest-UTC and BeginRequest-UTC make the fields after them fail to extract.

Third-party software attributions

Version 1.0.0 of the Splunk Add-on for Microsoft IIS does not incorporate any third-party software or libraries.

Last modified on 21 July, 2021
PREVIOUS
Release notes for the Splunk Add-on for Microsoft IIS
 

This documentation applies to the following versions of Splunk® Supported Add-ons: released


Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters