You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Windows Server 2008(Server-A)下架前如何收集活跃依赖清单?

Absolutely! IIS logs are your first stop for tracking client requests on a Windows Server 2008 web server, and they’re surprisingly straightforward to leverage for this exact decommissioning scenario. Let’s break this down, plus cover the other active dependency checks you need:

1. Using IIS Logs to Get Client Request Lists
  • Locate the log files first: On Windows Server 2008 (running IIS 7/7.5), logs are stored by default in %SystemDrive%\inetpub\logs\LogFiles. Each website has its own numbered subfolder (e.g., W3SVC1 for the first site you set up).
  • Focus on critical log fields: The standard W3C log format includes all the data you need to confirm active usage:
    • c-ip: The client IP address making the request
    • date/time: Timestamp of the request
    • cs-method: HTTP method (GET/POST/etc.)
    • cs-uri-stem: The specific resource requested (like /api/data or /home.html)
    • sc-status: HTTP status code (to verify successful, valid requests)
  • Filter for recent activity: To avoid sifting through years of logs, sort files by modified date (newest first) and focus on entries from the last 7-30 days. For faster parsing, use PowerShell to filter logs:
    Get-ChildItem "C:\inetpub\logs\LogFiles\W3SVC1" -Filter *.log | ForEach-Object {
        Get-Content $_.FullName | Where-Object { $_ -match "2024-0[4-5]" } # Replace with your target date range
    }
    
  • Quick sanity check: Ensure IIS logging is enabled for all websites (open IIS Manager > Select your site > Logging in the Features View). If logs were rotated or archived, don’t forget to check older compressed files too.
2. Other Active Dependency Checks for Server Decommissioning

Since you need a complete picture of active usage, don’t stop at IIS logs—here’s what else to collect:

Folder Access Activity

  • Audit via Event Viewer:
    1. Enable auditing on critical folders: Right-click the folder > Properties > Security > Advanced > Auditing > Add > Select a principal (e.g., "Everyone") > Check "Read", "Write", and "Modify" under "Access".
    2. Check Event Viewer > Windows Logs > Security for Event ID 4663 (file/folder access) and 4656 (handle requested) to see recent access activity.
  • PowerShell quick scan:
    Get-ChildItem "C:\YourCriticalFolder" -Recurse | Where-Object { $_.LastAccessTime -gt (Get-Date).AddDays(-30) } | Select-Object FullName, LastAccessTime
    

Task Triggers & Scheduled Tasks

  • Open Task Scheduler and navigate to the Task Scheduler Library. Look for tasks with a non-empty "Next Run Time" or recent "Last Run Time".
  • Export active tasks to a CSV for easy review:
    Get-ScheduledTask | Where-Object { $_.State -eq 'Ready' } | Select-Object TaskName, TaskPath, LastRunTime, NextRunTime | Export-Csv -Path "C:\ActiveScheduledTasks.csv" -NoTypeInformation
    
  • Pay attention to tasks with a "Last Run Result" of 0x0 (successful execution) in the last month.

Bonus Checks for Full Coverage

  • Active user sessions: Run quser in Command Prompt to see if any users are currently logged on (or recently disconnected).
  • Running services & dependencies: Open services.msc, check which services are running, and use the "Dependencies" tab to spot if other systems rely on services hosted here.
  • Network connections: Run netstat -ano to list active TCP/UDP connections—this can reveal ongoing communication with other servers or clients.

内容的提问来源于stack exchange,提问作者tech01230

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 10:32:31