Apache High Level Visitor Info

The following query gives a breakdown on traffic by clientip. I run this over all time so I can get detailed information on first visit versus latest visit as you can see below.

This will return something like the following: If you want to run this as a scheduled search, which I advise doing […]

Continue Reading →

Simple GeoIP Information for Web Traffic

This simple query will show if IIS traffic came to a given site from three geographical possibilities: “United States” “International” or “Unknown” sources. This relies entirely on geoip lookup. You can change the country of “United States” to anything you desire for you own data set (just make the change in the eval section below!). […]

Continue Reading →

Weekday Web Traffic Summary in IIS

The following Splunk query will show a summary of all weekday activity for a given website in IIS.

Continue Reading →

Visits by Hour of the Day in IIS

The following Splunk query will list the total visits for each hour in a given time range.

Continue Reading →

Total Hits on Most Active Day in IIS

The following Splunk query will return the total number of hits on the most active day in a given time range within an IIS environment:

Continue Reading →

Total Hits on Least Active Day in IIS

The following Splunk Query will return the total number of hits to a web site on the least active day of a given time range:

Continue Reading →

Most Active Day and Least Active Day for IIS Web Traffic

The following Splunk query will return the most active and the least active days for web traffic in an IIS environment:

Continue Reading →

Visits by Days of the Week in IIS

The following Splunk query will show the number of web visits for each weekday:

Continue Reading →