Hi
Devender RaoThank you for your previous assistance. After conducting several tests, I found that my other agent is able to successfully receive IIS logs. Apart from the difference in IIS versions, the agent versions are also different. Therefore, I reinstalled the agent and downgraded it to Wazuh v4.3.10, and now the logs can be successfully collected.
There are some differences in the logs between two version agent in the "archive.log."
-----------------------------------------------
config:
<localfile>
<location>D:\WEBWEP_log\W3SVC1\*.log</location>
<log_format>iis</log_format>
</localfile>
-----------------------------------------------
Version v4.3.10:
2023 Jun 27 14:16:14 (WEBAPP) any->\WEBWEP_log\W3SVC1\u_ex230627.log 2023-06-27 06:16:04 10.1.0.41 GET /WebAAA/common/images/icon/icon_m19.gif - 80 - 10.1.0.102 Mozilla/5.0+(Windows+NT+6.1;+Win64;+x64;+rv:109.0)+Gecko/20100101+Firefox/114.0 404 0 2 3
2023 Jun 27 14:16:14 (WEBAPP) any->\WEBWEP_log\W3SVC1\u_ex230627.log 2023-06-27 06:16:04 10.1.0.41 GET /WebAAA/common/images/icon/icon_m97.gif - 80 - 10.1.0.102 Mozilla/5.0+(Windows+NT+6.1;+Win64;+x64;+rv:109.0)+Gecko/20100101+Firefox/114.0 200 0 0 9
2023 Jun 27 14:16:14 (WEBAPP) any->\WEBWEP_log\W3SVC1\u_ex230627.log 2023-06-27 06:16:04 10.1.0.41 GET /WebAAA/common/images/icon/icon_m19.gif - 80 - 10.1.0.102 Mozilla/5.0+(Windows+NT+6.1;+Win64;+x64;+rv:109.0)+Gecko/20100101+Firefox/114.0 404 0 2 1
2023 Jun 27 14:16:14 (WEBAPP) any->\WEBWEP_log\W3SVC1\u_ex230627.log 2023-06-27 06:16:04 10.1.0.41 GET /WebAAA/common/images/icon/icon_m66.gif - 80 - 10.1.0.102 Mozilla/5.0+(Windows+NT+6.1;+Win64;+x64;+rv:109.0)+Gecko/20100101+Firefox/114.0 200 0 0 203
-----------------------------------------------
Version v4.4.3
2023 Jun 27 13:37:17 (WEBAPP) any->D| \WEBWEP_log\W3SVC1\u_ex230627.log:2023-06-27 05:36:47 10.1.0.41 GET /WebAAA/Common/Style/font-awesome/fonts/fontawesome-webfont.woff2 v=4.5.0 443 - 60.249.95.11 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64;+rv:109.0)+Gecko/20100101+Firefox/114.0 404 3 50 6
2023 Jun 27 13:37:17 (WEBAPP) any->D| \WEBWEP_log\W3SVC1\u_ex230627.log:2023-06-27 05:36:47 10.1.0.41 POST /WebAAA/Login.aspx ReturnUrl=%2fgvceip%2f 443 - 60.249.95.11 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64;+rv:109.0)+Gecko/20100101+Firefox/114.0 200 0 64 56
2023 Jun 27 13:37:17 (WEBAPP) any->D| \WEBWEP_log\W3SVC1\u_ex230627.log:2023-06-27 05:36:47 10.1.0.41 GET /WebAAA/Common/Style/font-awesome/fonts/fontawesome-webfont.woff v=4.5.0 443 - 60.249.95.11 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64;+rv:109.0)+Gecko/20100101+Firefox/114.0 404 3 50 6
2023 Jun 27 13:37:17 (WEBAPP) any->D| \WEBWEP_log\W3SVC1\u_ex230627.log:2023-06-27 05:36:48 10.1.0.41 POST /WebAAA/Login.aspx ReturnUrl=%2fgvceip%2f 443 - 60.249.95.11 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64;+rv:109.0)+Gecko/20100101+Firefox/114.0 200 0 0 561
2023 Jun 27 13:37:17 (WEBAPP) any->D| \WEBWEP_log\W3SVC1\u_ex230627.log:2023-06-27 05:36:48 10.1.0.41 GET /WebAAA/App_Themes/ThirdTheme/images/icon/icon_m17.gif - 443 - 10.1.5.107 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/
109.0.0.0+Safari/537.36 404 0 2 0
-----------------------------------------------
I'm not sure why the new version includes "D |" in the path, and it's unclear if this is the cause of the issue. However, I wanted to inform you that my issue has already been resolved. I'm providing these records for your reference. If there is a need for further testing or any other assistance, I would be happy to help.
Renee Lin 在 2023年6月26日 星期一上午9:42:51 [UTC+8] 的信中寫道: