IIS binded site query

Comments

1 comment

  • Avatar
    Harinder Bhandari

    Can you please try this query:

    _source="IIS_source" and _collector="test1"
    | parse regex "(?<server_ip>\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}) (?<method>\S+) (?<cs_uri_stem>\S+) (?<cs_uri_query>\S+) (?<s_port>\S+) (?<cs_username>\S+) (?<c_ip>\S+) (?<cs_User_Agent>\S+?) (?<cs_referer>\S+) (?<sc_status>\S+) (?<sc_substatus>\S+?) (?<sc_win32_status>\S+?) (?<time_taken>\S+)"
    | where cs_referer matches "http://test.tv*"
    | count by cs_referer, c_ip
    0
    Comment actions Permalink

Please sign in to leave a comment.