Microsoft IIS W3C

image

Self Service Ingestion

Connect this data source on your own, using the Hunters platform.

Overview

The IIS W3C logging format is a standard format used by Microsoft's Internet Information Services (IIS) to log detailed information about web requests. This format is widely used for its comprehensive coverage of web server activities, including details such as client IP addresses, user names, request timestamps, HTTP status codes, and bytes transferred. These logs are invaluable for monitoring and analyzing web server performance, identifying security issues, and troubleshooting application problems.

Table name: IIS_W3C

Send data to Hunters

Hunters support the collection of IIS W3C logs via an intermediary AWS S3 bucket.

To connect IIS W3C logs:

  1. Gather IIS W3C logs using an on-prem utility and transfer them into an AWS S3 bucket.
  2. Once the export is completed and the logs are collected to S3, follow the steps in this section.

Expected format

Logs are expected in CEF format.

Sample

2020-12-26 22:00:00 O.O.O.O GET / - 443 - O.O.O.O Amazon-abc-def-ghi-Service+(ref+89b623a4-3399-4fdb-8188-5a2fc8f46f8b;+report+http://abc.to/1vsZADi) - 200 0 0 222