Remotely Monitoring IIS Log Files

Rainer Gerhards, Tina Bird · 2003

Web server log files are a very valuable source of forensic data for intrusion detection and overall network monitoring. Nevertheless, they are hard to integrate in a central system, especially in a real-time log monitoring infrastructure. In this document, we focus on Microsoft’s Internet Information Server (IIS) log files and how to forward them to a central log repository. We describe the information contained in IIS server access logs, the way IIS log files are generated and a technique for forwarding them to a central log repository. While this paper focuses on IIS log files, the same methodology can of course be applied to any other text log file on a Windows host, for example logs from Apache or DHCP. Please note that this document is correct for IIS up to version 5.1. Microsoft has announced considerable change for IIS 6.0, and the information in this document might not be valid for that version.

Read the paper · More papers on PaperTik