Security Compliance

SEM - IIS Advanced Logging

This article describes how to set up the Microsoft IIS W3C Advanced Logging connector for SEM.

First published date

10/31/2018 4:44 PM

Last published date

6/9/2025 3:21 PM

Overview

This article explains how to set up the Microsoft IIS W3C Advanced Logging connector for Security Event Manager (formerly Log & Event Manager).

Product section

Security Event Manager

Resolution

Set up the connector to receive the logs 

  1. Open the connectors on the node where IIS has been installed:
    Configure > Nodes > Select Node > Manage node connectors

    image.png

  2. Type IIS in the search bar, Find the Microsoft IIS Advanced Logging Connector, Select it and click Add Connector:

    image.png

  3. Set up the IIS Advanced Logging Connector to point at the correct log file location: Make sure to review the folder path on the node.

    image.png

  4. Set the correct prefix and postfix for the log files in that location: Make sure to look at the log file on the node.

     

    image.png

  5. Save the Connector and Start it:

    image.png

 

Check for the Logging 

  1. Create a Filter in the Live Events > Filters area of the SEM Web Console watch the incoming data using AnyAlert.ToolAlias=*Microsoft IIS W3C Advanced Logging* (make sure to modify the name if you changed the alias on the connector) and save the Filter:

    image.png

  2. If you are seeing data the IIS logging has started. If not, you will need to check the following items in IIS.

 

Set up IIS to send the logs to the log file in the correct format 

  1. Open IIS and select the Logging:

    image.png

  2. On the Logging page click on the [Select Fields...] button to open the Select Logging Fields page:

    image.png

  3. Make sure to select all the items are checked on the Select Logging Fields page:
     

    image.png

  4. Apply the settings and restart IIS and the logging should start to come in after a few minutes.

Note: If X-Forward Log field is not showing up in LEM web console, then make sure the "Microsoft IIS Web Server 5.0 (W3C Extended file format)"

Contact SolarWinds Technical Support if this does not cause the Advanced IIS logs to begin showing up on the SEM.