Skip to content

SharePoint Server Logs (SPSE) parser #1255

@respondersGY

Description

@respondersGY

These logs are very useful to detect ToolShell exploitation events. The most useful logs use the following naming scheme: HOSTNAME-YYYYMMDD-<NUMBER>.log.

Timestamp               Process                                         TID     Area                            Category                        EventID Level           Message         Correlation
MM/DD/YYYY HH:MM:ss  w3wp.exe (XXX)                               XXXX  SharePoint Foundation           General                         XXXX    Medium          Application error when access /_layouts/15/spinstall0.aspx, Error=The file '/_layouts/15/spinstall0.aspx' does not exist.  [...]

References

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions