hi all
I want to understand IIS logs but I don't know when I do some operation such as add, delete or edit site or application pools which logs would generate.(eventid 29)
Also what is the "EditOperationType" field in log and when it will be 1, 2 or 3? (see following)
can anyone help me?
2020-02-12T14:19:41.709346+03:30 mail.nsoc.com Microsoft-Windows-IIS-Configuration[3800] {"EventTime":"2020-02-12 14:19:41","Hostname":"mail.nsoc.com","Keywords":4611686018427387904,"EventType":"VERBOSE","SeverityValue":1,"Severity":"DEBUG","EventID":29,"SourceName":"Microsoft-Windows-IIS-Configuration","ProviderGuid":"{DC0B8E51-4863-407A-BC3C-1B479B2978AC}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":1350,"ProcessID":3800,"ThreadID":2604,"Channel":"Microsoft-IIS-Configuration/Operational","Domain":"NSOC","AccountName":"Administrator","UserID":"S-1-5-21-1134574511-1599781384-3540602214-500","AccountType":"User","Message":"Changes
to '/system.applicationHost/applicationPools/add[@name=\"sss\"]/recycling/periodicRestart/@time' at 'MACHINE/WEBROOT/APPHOST' have successfully been committed.","Opcode":"Info","PhysicalPath":"\\\\?\\C:\\Windows\\system32\\inetsrv\\config\\applicationHost.config","ConfigPath":"MACHINE/WEBROOT/APPHOST","Configuration":"/system.applicationHost/applicationPools/add[@name=\"sss\"]/recycling/periodicRestart/@time","EditOperationType":"1","OldValue":"1.05:00:00","NewValue":"1.02:04:00","EventReceivedTime":"2020-02-12
14:19:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}#015
2020-02-09T13:51:39.436880+03:30 mail.nsoc.com Microsoft-Windows-IIS-Configuration[1696] {"EventTime":"2020-02-09 13:51:39","Hostname":"mail.nsoc.com","Keywords":4611686018427387904,"EventType":"VERBOSE","SeverityValue":1,"Severity":"DEBUG","EventID":29,"SourceName":"Microsoft-Windows-IIS-Configuration","ProviderGuid":"{DC0B8E51-4863-407A-BC3C-1B479B2978AC}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":4104,"ProcessID":1696,"ThreadID":1772,"Channel":"Microsoft-IIS-Configuration/Operational","Domain":"NT
AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Changes to '/system.applicationHost/listenerAdapters' at 'MACHINE/WEBROOT/APPHOST' have successfully been committed.","Opcode":"Info","PhysicalPath":"\\\\?\\C:\\inetpub\\temp\\apppools\\APC983A.tmp","ConfigPath":"MACHINE/WEBROOT/APPHOST","Configuration":"/system.applicationHost/listenerAdapters","EditOperationType":"2","EventReceivedTime":"2020-02-09
13:51:41","SourceModuleName":"in_windows_events","SourceModuleType":"im_msvistalog"}#015
2020-02-12T15:13:25.626608+03:30 mail.nsoc.com Microsoft-Windows-IIS-Configuration[2880] {"EventTime":"2020-02-12 15:13:25","Hostname":"mail.nsoc.com","Keywords":4611686018427387904,"EventType":"VERBOSE","SeverityValue":1,"Severity":"DEBUG","EventID":29,"SourceName":"Microsoft-Windows-IIS-Configuration","ProviderGuid":"{DC0B8E51-4863-407A-BC3C-1B479B2978AC}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":1396,"ProcessID":2880,"ThreadID":2296,"Channel":"Microsoft-IIS-Configuration/Operational","Domain":"NSOC","AccountName":"Administrator","UserID":"S-1-5-21-1134574511-1599781384-3540602214-500","AccountType":"User","Message":"Changes
to '/system.applicationHost/applicationPools/add[@name=\"testSOC1\"]/@autoStart' at 'MACHINE/WEBROOT/APPHOST' have successfully been committed.","Opcode":"Info","PhysicalPath":"\\\\?\\C:\\Windows\\system32\\inetsrv\\config\\applicationHost.config","ConfigPath":"MACHINE/WEBROOT/APPHOST","Configuration":"/system.applicationHost/applicationPools/add[@name=\"testSOC1\"]/@autoStart","EditOperationType":"3","OldValue":"false","NewValue":"true","EventReceivedTime":"2020-02-12
15:13:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}#015