Microsoft IIS log source parameters for Microsoft IIS Server
If QRadar does not automatically detect the log source, add a Microsoft IIS Server log source on the QRadar Console by using the Microsoft IIS protocol.
When using the Microsoft IIS protocol, there are specific parameters that you must use.
Parameter | Value |
---|---|
Log Source type | Microsoft IIS Server |
Protocol Configuration | Microsoft IIS |
Log Source Identifier |
Type the IP address or host name for the log source. |
File Pattern |
Type the regular expression (regex) that is needed to filter the file names. All matching files
are included in the processing. The default is For example, to list all files that start with the word log, followed by one or more digits and
ending with tar.gz, use the following entry:
|
For a complete list of Microsoft IIS protocol parameters and their values, see Microsoft IIS protocol configuration options.