Log processing rule
Question asked by Peter S - 9/16/2024 at 10:46 AM
How do I exclude unauthenticated users from IIS logs using the log processing rule (or some other way)?

The app I'm capturing logs from are Windows authentication, however sometimes the logs contain things like GET / - 443 - client IP (etc) instead of the typical GET / - 443 domain\user client IP (etc).  I need to filter out the former to only show stats for authenticated users...

1 Reply

Reply to Thread
Tony Scholz Replied
Employee Post

The best way to tackle this issue is going to be by adding a Filter to remove this from the report. Another option would be a log processing rule. 

This will take some trial and error to remove it the way you want depending on how it is read into the processed data. I do not have any logs like this to test on but some things to try would be 
  • N/A
  • No Username
  • {blank_line}
Hope this helps. 
Tony Scholz System/Network Administrator SmarterTools Inc. www.smartertools.com

Reply to Thread