- play_arrow What's New in WinCollect
- play_arrow WinCollect Overview
- play_arrow Installation Prerequisites for WinCollect
- play_arrow WinCollect installations
- WinCollect installations
- Installing and Upgrading the WinCollect Application on JSA Appliances
- Creating an Authentication Token for WinCollect Agents
- Adding Multiple Destinations to WinCollect Agents
- Migrating WinCollect Agents After a JSA Hardware Upgrade
- Stand-alone WinCollect Installations
- WinCollect Configuration Console Overview
- Installing the Configuration Console
- Silently Installing, Upgrading, and Uninstalling WinCollect Software
- Setting an XPath Parameter During Automated Installation
- Migrating from Adaptive Log Exporter to WinCollect
- Installing the WinCollect Agent on a Windows Host
- Installing a WinCollect Agent from the Command Prompt
- Uninstalling a WinCollect Agent from the Command Prompt
- Uninstalling a WinCollect Agent from the Control Panel
- play_arrow Configuring WinCollect Agents After Installation
- Configuring WinCollect Agents After Installation
- Manually Adding a WinCollect Agent
- Deleting a WinCollect Agent
- WinCollect Destinations
- Adding Custom Entries to WinCollect Status Messages
- Forwarding Events Identifier
- Configuring Stand-alone WinCollect Agents with the Configuration Console
- Creating a WinCollect Credential
- Adding a Destination to the WinCollect Configuration Console
- Configuring a Destination with TLS in the WinCollect Configuration Console
- Adding a Device to the WinCollect Configuration Console
- Sending Encrypted Events to JSA
- Increasing UDP Payload Size
- Include Milliseconds in Event Log Timestamp
- Collecting Local Windows Logs
- Collecting Remote Windows Logs
- Changing configuration with Templates in a Stand-alone Deployment
- Configuration Options for Systems with Restricted Policies for Domain Controller Credentials
- play_arrow Troubleshooting WinCollect Deployment Issues
- Troubleshooting WinCollect Deployment Issues
- Common Problems
- Replacing the Default Certificate in JSA Generates Invalid PEM Errors
- The Statistics Subsystem
- Event ID 1003 Splits the Message in JSA
- WinCollect Files are Not Restored During a Configuration Restore
- Windows 10 (1803) Cannot Read the Security Bookmark File
- Resolving Log Source Error After WinCollect Update
- WinCollect Log File
WinCollect Microsoft IIS Log Source Configuration Options
You can configure a log source to use the Microsoft Internet Information Services (IIS). This WinCollect plugin supports a single point of collection for W3C format log files that are on a Microsoft IIS web server.
Overview for the WinCollect Plug-in for Microsoft IIS
You can use one of two methods to collect Microsoft IIS logs with WinCollect. You can install an agent locally on your Microsoft IIS server and configure it accordingly. Or, with WinCollect 7.2.8 and later, you can configure a WinCollect agent to remotely poll the IIS logs. See Table 1 for setting up the directory paths based off your method of log collection.
The WinCollect plug-in for Microsoft IIS can read and forward events for the following logs:
Website (W3C) logs
File Transfer Protocol (FTP) logs
Simple Mail Transfer Protocol (SMTP) logs
Network News Transfer Protocol (NNTP) logs
The WinCollect plug-in for Microsofct IIS can monitor W3C, IIS, and NCSA formatted event logs. However, the IIS and NCSA event formats do not contain as much event information in their event payloads as the W3C event format. To collect the maximum information available, configure your Microsoft IIS Server to write events in W3C format. WinCollect can collect both ASCII and UTF-8 encoded event log files.
Supported Versions Of Microsoft IIS
The Microsoft IIS plug-in for WinCollect supports the following Microsoft IIS software versions:
Microsoft IIS Server 7.0
Microsoft IIS Server 7.5
Microsoft IIS Server 8.0
Microsoft IIS Server 8.5
Microsoft IIS Server 10
WinCollect Microsoft IIS Parameters
Parameter | Description |
---|---|
Protocol Configuration | Select WinCollect Microsoft IIS. |
Log Source Identifier | The IP address or host name of your Microsoft IIS server. It must be unique for the log source type. |
Root Directory | The directory path to your Microsoft IIS log files. For Microsoft 7.0-10.0 (full site), use:
For Microsoft IIS 7.0-10.0 (individual site), use:
|
Polling Interval | The amount of time between queries to the root log directory for new events. The default polling interval is 5000 milliseconds. |
FTP | Collects File Transfer Protocol (FTP) events from Microsoft IIS. |
NNTP/News | Collects Network News Transfer Protocol (NNTP) events from Microsoft IIS. |
SMTP/Mail | Collects Simple Mail Transfer Protocol (SMTP) events from Microsoft IIS. |
W3C | Collects website (W3C) events from Microsoft IIS. |
WinCollect Agent | Manages the WinCollect agent log source. |
For more information about configuring a Microsoft IIS log source, see the Configuring DSMs Guide.