使用LogParser 2.2遇IIS日志未知字段错误,求助用户最后登录时间查询问题
Hey there! Let's break down your two LogParser 2.2 problems step by step—first-time hurdles with this tool are super common, so let's get you sorted.
1. Unknown Field Error When Fetching IIS Log Data
This almost always boils down to a mismatch between the fields you're querying and the actual fields present in your IIS logs (or LogParser not recognizing your log format correctly). Here's how to fix it:
- Verify your IIS log field set: Open IIS Manager, navigate to your site's logging settings, and check the "Select Fields" list. Note every enabled field (they look like
cs-username,cs-host,date, etc.—these are case-insensitive but must match exactly in your query). - Use the correct input format: Make sure you're adding
-i:IISW3Cto your command (this tells LogParser to use the IIS W3C log schema). For example:LogParser.exe "SELECT date, time, cs-username FROM ex*.log" -i:IISW3C - Skip header comments: If your logs start with comment lines (like
#Fields: date time ...), LogParser might sometimes misread these. Add-nSkipLines:4(adjust the number based on how many comment lines your logs have) to skip them:LogParser.exe "SELECT * FROM ex0901.log" -i:IISW3C -nSkipLines:4 - Avoid custom field typos: If you added custom fields to your IIS logs, double-check their exact names in the log header and mirror them in your query.
2. Error When Querying User Last Login Time
The issue here depends on what "last login" you're targeting—Windows security log logins, or authenticated IIS access. Let's cover both scenarios:
Scenario A: Querying Windows Security Log for Last Login
If you're trying to pull from Windows Event Logs (security events), you need to target the right event ID and use the correct fields:
- Use the EVT input format: Add
-i:EVTand target the Security log. Successful logins are Event ID 4624 (for Windows Server 2008+; older versions use 528). - Correct your query syntax: A working example looks like this (run LogParser as Administrator—you need permissions to read the Security log):
LogParser.exe "SELECT TargetUserName, MAX(TimeGenerated) AS LastLoginTime FROM Security WHERE EventID=4624 GROUP BY TargetUserName ORDER BY LastLoginTime DESC" -i:EVT - Common mistakes: Using
usernameinstead ofTargetUserName, forgetting to filter by Event ID, or running without admin rights (which blocks access to the Security log).
Scenario B: Querying IIS Logs for Last Authenticated Access
If "last login" refers to when a user last accessed your site via authenticated IIS access:
- Filter out anonymous users: IIS logs mark anonymous users with
-incs-username, so exclude those. - Merge date and time: IIS logs store date and time as separate fields—use
date + ' ' + timeorTO_TIMESTAMP(date, time)to create a single timestamp. - Working query example:
LogParser.exe "SELECT cs-username, MAX(TO_TIMESTAMP(date, time)) AS LastAccessTime FROM ex*.log WHERE cs-username <> '-' GROUP BY cs-username ORDER BY LastAccessTime DESC" -i:IISW3C - Common mistakes: Forgetting to exclude anonymous users, using the wrong field name for the username, or not merging date/time (which breaks the
MAX()aggregation).
Quick Pro Tip
Before writing complex queries, run a simple SELECT * FROM your-log-source LIMIT 10 to preview all available fields. This helps you confirm exactly what field names you should be using.
内容的提问来源于stack exchange,提问作者gchq

