Flat File - Microsoft IIS FTP W3C Extended Format
The W3C Extended log file format is the default log file format for IIS. It is a customizable ASCII text-based format. You can use IIS Manager to select which boxes to include in the log file, which enables you to keep log files as small as possible. To collect and process logs using the default LogRhythm MPE Rules sets you must leave the format in its default state. Adding any additional boxes to the output format will cause processing to fail. Because HTTP.sys handles the W3C Extended log file format, this format records HTTP.sys kernel-mode cache hits.
Prerequisites
- Ensure the IIS Active log format = W3C Extended Log File Format.
- Identify the following prior to configuration:
- The Microsoft IIS default log directory
- The LogRhythm System Monitor Agent used to collect the logs from Microsoft IIS Manager
Configure Default Log Directory and Active Log FTP W3C Extended Format in Microsoft IIS Manager
- Start Internet Information Services (IIS) Manager.
- Access ServerName, then FTP Sites.
- Right-click the FTP site where you want to enable logging and select Properties from the context menu.
- Click the FTP Site tab.
- Select the Engage logging check box.
- In the Active log format box, select W3C Extended Log Format.
- Next to the Active log format, click Properties.
- Specify the log file directory, for example:
C:\Windows\System32\LogFiles\IISFTPW3C_logs\.
After you configure the device, you must also configure LogRhythm according to the instructions provided on the overview page of this guide. The files being collected must be viewable on the host with the Agent using a standard file name path such as: /var/log/logfile.txt or C:\logs\logfile.txt.
Only Global Admins or Restricted Admins with elevated View and Manage privileges can take this action.
The name of the log message source is Flat File - Microsoft IIS FTP W3C Extended Format. In addition, when configuring this log source:
- For Log Message Processing Engine (MPE) Policy, select LogRhythm Default.
- On the Flat File Settings tab, enter the following:
- File Path. C:\Windows\System32\LogFiles\IISFTPW3C_logs\*.log
- Date Parsing Format. IIS FTP W3C Log [<UTC><yy>-<M>-<d> <h>:<m>:<s>]
- Log Message Start Regex. ^\d