A server side include file has included itself or the maximum depth of server side includes has been exceeded
Property
Value
Severity
1
Enabled
True
AutoMitigate
True
EvaluationFrequency
PT15M
WindowSize
PT15M
Type
rows
Query
Event | where EventID in (2221) and EventLog == ‘Application’ and Source == ‘Microsoft-Windows-IIS-W3SVC-WP’
Threshold
N/A
xPathQuery
System!*[System[Provider[@Name=‘Microsoft-Windows-IIS-W3SVC’] and (EventID=1071 or EventID=1073)]]
Application Pool has an IdleTimeout equal to or greater than the PeriodicRestart time
Property
Value
Severity
1
Enabled
True
AutoMitigate
True
EvaluationFrequency
PT15M
WindowSize
PT15M
Type
rows
Query
Event | where EventID in (5152) and EventLog == ‘System’ and Source == ‘Microsoft-Windows-WAS’
Threshold
N/A
xPathQuery
System!*[System[Provider[@Name=‘Microsoft-Windows-IIS-W3SVC’] and (EventID=1135 or EventID=1134)]]
Application Pool worker process is unresponsive
Property
Value
Severity
1
Enabled
True
AutoMitigate
True
EvaluationFrequency
PT15M
WindowSize
PT15M
Type
rows
Query
Event | where EventID in (5010,5011,5012,5013) and EventLog == ‘System’ and Source == ‘Microsoft-Windows-WAS’
Threshold
N/A
xPathQuery
Application!*[System[Provider[@Name=‘Microsoft-Windows-IIS-W3SVC-WP’] and (EventID=2226 or EventID=2230 or EventID=2231 or EventID=2232)]]
Application Pool worker process terminated unexpectedly
Property
Value
Severity
1
Enabled
True
AutoMitigate
True
EvaluationFrequency
PT15M
WindowSize
PT15M
Type
rows
Query
Event | where EventID in (5009) and EventLog == ‘System’ and Source == ‘Microsoft-Windows-WAS’
Threshold
N/A
xPathQuery
Application!*[System[Provider[@Name=‘Microsoft-Windows-IIS-W3SVC-WP’] and (EventID=2274 or EventID=2268 or EventID=2220 or EventID=2219 or EventID=2214)]]
ASP application error occurred
Property
Value
Severity
1
Enabled
True
AutoMitigate
True
EvaluationFrequency
PT15M
WindowSize
PT15M
Type
rows
Query
Event | where EventID in (500,499,23,22,21,20,19,18,17,16,9,8,7,6,5) and EventLog == ‘Application’ and Source == ‘Active Server Pages’
Threshold
N/A
xPathQuery
System!*[System[Provider[@Name=‘Microsoft-Windows-WAS’] and (EventID=5172 or EventID=5173)]]
HTTP control channel for the WWW Service did not open
Property
Value
Severity
1
Enabled
True
AutoMitigate
True
EvaluationFrequency
PT15M
WindowSize
PT15M
Type
rows
Query
Event | where EventID in (1037) and EventLog == ‘System’ and Source == ‘Microsoft-Windows-IIS-W3SVC’
Threshold
N/A
xPathQuery
System!*[System[Provider[@Name=‘Microsoft-Windows-WAS’] and (EventID=5174 or EventID=5179 or EventID=5180)]]
HTTP Server could not create a client connection object for user
Property
Value
Severity
1
Enabled
True
AutoMitigate
True
EvaluationFrequency
PT15M
WindowSize
PT15M
Type
rows
Query
Event | where EventID in (2208) and EventLog == ‘Application’ and Source == ‘Microsoft-Windows-IIS-W3SVC-WP’
Threshold
N/A
xPathQuery
System!*[System[Provider[@Name=‘Microsoft-Windows-WAS’] and (EventID=5152)]]
HTTP Server could not create the main connection socket
Property
Value
Severity
1
Enabled
True
AutoMitigate
True
EvaluationFrequency
PT15M
WindowSize
PT15M
Type
rows
Query
Event | where EventID in (2206) and EventLog == ‘Application’ and Source == ‘Microsoft-Windows-IIS-W3SVC-WP’
Threshold
N/A
xPathQuery
System!*[System[Provider[@Name=‘Microsoft-Windows-IIS-W3SVC’] and (EventID=1037)]]
HTTP Server could not initialize its security
Property
Value
Severity
1
Enabled
True
AutoMitigate
True
EvaluationFrequency
PT15M
WindowSize
PT15M
Type
rows
Query
Event | where EventID in (2201) and EventLog == ‘Application’ and Source == ‘Microsoft-Windows-IIS-W3SVC-WP’
Threshold
N/A
xPathQuery
System!*[System[Provider[@Name=‘Microsoft-Windows-IIS-W3SVC’] and (EventID=1062)]]
HTTP Server could not initialize the socket library
Property
Value
Severity
1
Enabled
True
AutoMitigate
True
EvaluationFrequency
PT15M
WindowSize
PT15M
Type
rows
Query
Event | where EventID in (2203) and EventLog == ‘Application’ and Source == ‘Microsoft-Windows-IIS-W3SVC-WP’
Threshold
N/A
xPathQuery
System!*[System[Provider[@Name=‘Microsoft-Windows-IIS-W3SVC’] and (EventID=1126)]]
HTTP Server was unable to initialize due to a shortage of available memory
Property
Value
Severity
1
Enabled
True
AutoMitigate
True
EvaluationFrequency
PT15M
WindowSize
PT15M
Type
rows
Query
Event | where EventID in (2204) and EventLog == ‘Application’ and Source == ‘Microsoft-Windows-IIS-W3SVC-WP’
Threshold
N/A
xPathQuery
System!*[System[Provider[@Name=‘Microsoft-Windows-IIS-W3SVC’] and (EventID=1133)]]
ISAPI application error detected
Property
Value
Severity
1
Enabled
True
AutoMitigate
True
EvaluationFrequency
PT15M
WindowSize
PT15M
Type
rows
Query
Event | where EventID in (2274,2268,2220,2219,2214) and EventLog == ‘Application’ and Source == ‘Microsoft-Windows-IIS-W3SVC-WP’
Threshold
N/A
xPathQuery
System!*[System[Provider[@Name=‘Microsoft-Windows-IIS-W3SVC’] and (EventID=1173)]]
Job object associated with the application pool encountered an error
Property
Value
Severity
1
Enabled
True
AutoMitigate
True
EvaluationFrequency
PT15M
WindowSize
PT15M
Type
rows
Query
Event | where EventID in (5088,5061,5060) and EventLog == ‘System’ and Source == ‘Microsoft-Windows-WAS’
Threshold
N/A
xPathQuery
System!*[System[Provider[@Name=‘Microsoft-Windows-IIS-W3SVC’] and (EventID=1175)]]
Module has an invalid precondition
Property
Value
Severity
1
Enabled
True
AutoMitigate
True
EvaluationFrequency
PT15M
WindowSize
PT15M
Type
rows
Query
Event | where EventID in (2296) and EventLog == ‘Application’ and Source == ‘Microsoft-Windows-IIS-W3SVC-WP’
Threshold
N/A
xPathQuery
Application!*[System[Provider[@Name=‘Microsoft-Windows-IIS-W3SVC-WP’] and (EventID=2201)]]
Module registration error detected (failed to find RegisterModule entrypoint)
Property
Value
Severity
1
Enabled
True
AutoMitigate
True
EvaluationFrequency
PT15M
WindowSize
PT15M
Type
rows
Query
Event | where EventID in (2295) and EventLog == ‘Application’ and Source == ‘Microsoft-Windows-IIS-W3SVC-WP’
Threshold
N/A
xPathQuery
Application!*[System[Provider[@Name=‘Microsoft-Windows-IIS-W3SVC-WP’] and (EventID=2203)]]
Module registration error detected (module returned an error during registration)
Property
Value
Severity
1
Enabled
True
AutoMitigate
True
EvaluationFrequency
PT15M
WindowSize
PT15M
Type
rows
Query
Event | where EventID in (2293) and EventLog == ‘Application’ and Source == ‘Microsoft-Windows-IIS-W3SVC-WP’
Threshold
N/A
xPathQuery
Application!*[System[Provider[@Name=‘Microsoft-Windows-IIS-W3SVC-WP’] and (EventID=2204)]]
Only one type of logging can be enabled at a time
Property
Value
Severity
1
Enabled
True
AutoMitigate
True
EvaluationFrequency
PT15M
WindowSize
PT15M
Type
rows
Query
Event | where EventID in (1133) and EventLog == ‘System’ and Source == ‘Microsoft-Windows-IIS-W3SVC’
Threshold
N/A
xPathQuery
Application!*[System[Provider[@Name=‘Microsoft-Windows-IIS-W3SVC-WP’] and (EventID=2206)]]
SF_NOTIFY_READ_RAW_DATA filter notification is not supported in IIS 8
Property
Value
Severity
1
Enabled
True
AutoMitigate
True
EvaluationFrequency
PT15M
WindowSize
PT15M
Type
rows
Query
Event | where EventID in (2261) and EventLog == ‘Application’ and Source == ‘Microsoft-Windows-IIS-W3SVC-WP’
Threshold
N/A
xPathQuery
Application!*[System[Provider[@Name=‘Microsoft-Windows-IIS-W3SVC-WP’] and (EventID=2208)]]
The configuration manager for WAS did not initialize
Property
Value
Severity
2
Enabled
True
AutoMitigate
True
EvaluationFrequency
PT15M
WindowSize
PT15M
Type
rows
Query
Event | where EventID in (5036) and EventLog == ‘System’ and Source == ‘Microsoft-Windows-WAS’
Threshold
N/A
xPathQuery
Application!*[System[Provider[@Name=‘Microsoft-Windows-IIS-W3SVC-WP’] and (EventID=2218)]]
The directory specified for caching compressed content is invalid
Property
Value
Severity
1
Enabled
True
AutoMitigate
True
EvaluationFrequency
PT15M
WindowSize
PT15M
Type
rows
Query
Event | where EventID in (2264) and EventLog == ‘Application’ and Source == ‘Microsoft-Windows-IIS-W3SVC-WP’
Threshold
N/A
xPathQuery
Application!*[System[Provider[@Name=‘Microsoft-Windows-IIS-W3SVC-WP’] and (EventID=2227)]]
The Global Modules list is empty
Property
Value
Severity
1
Enabled
True
AutoMitigate
True
EvaluationFrequency
PT15M
WindowSize
PT15M
Type
rows
Query
Event | where EventID in (2298) and EventLog == ‘Application’ and Source == ‘Microsoft-Windows-IIS-W3SVC-WP’
Threshold
N/A
xPathQuery
Application!*[System[Provider[@Name=‘Microsoft-Windows-IIS-W3SVC-WP’] and (EventID=2233)]]
The HTTP server encountered an error processing the server side include file
Property
Value
Severity
1
Enabled
True
AutoMitigate
True
EvaluationFrequency
PT15M
WindowSize
PT15M
Type
rows
Query
Event | where EventID in (2218) and EventLog == ‘Application’ and Source == ‘Microsoft-Windows-IIS-W3SVC-WP’
Threshold
N/A
xPathQuery
Application!*[System[Provider[@Name=‘Microsoft-Windows-IIS-W3SVC-WP’] and (EventID=2258)]]
The server failed to close client connections to URLs during shutdown
Property
Value
Severity
1
Enabled
True
AutoMitigate
True
EvaluationFrequency
PT15M
WindowSize
PT15M
Type
rows
Query
Event | where EventID in (2258) and EventLog == ‘Application’ and Source == ‘Microsoft-Windows-IIS-W3SVC-WP’
Threshold
N/A
xPathQuery
Application!*[System[Provider[@Name=‘Microsoft-Windows-IIS-W3SVC-WP’] and (EventID=2261)]]
The server was unable to acquire a license for a SSL connection
Property
Value
Severity
1
Enabled
True
AutoMitigate
True
EvaluationFrequency
PT15M
WindowSize
PT15M
Type
rows
Query
Event | where EventID in (2227) and EventLog == ‘Application’ and Source == ‘Microsoft-Windows-IIS-W3SVC-WP’
Threshold
N/A
xPathQuery
Application!*[System[Provider[@Name=‘Microsoft-Windows-IIS-W3SVC-WP’] and (EventID=2264)]]
The server was unable to allocate a buffer to read a file
Property
Value
Severity
1
Enabled
True
AutoMitigate
True
EvaluationFrequency
PT15M
WindowSize
PT15M
Type
rows
Query
Event | where EventID in (2233) and EventLog == ‘Application’ and Source == ‘Microsoft-Windows-IIS-W3SVC-WP’
Threshold
N/A
xPathQuery
Application!*[System[Provider[@Name=‘Microsoft-Windows-IIS-W3SVC-WP’] and (EventID=2281)]]
The server was unable to read a file
Property
Value
Severity
1
Enabled
True
AutoMitigate
True
EvaluationFrequency
PT15M
WindowSize
PT15M
Type
rows
Query
Event | where EventID in (2226,2230,2231,2232) and EventLog == ‘Application’ and Source == ‘Microsoft-Windows-IIS-W3SVC-WP’
Threshold
N/A
xPathQuery
Application!*[System[Provider[@Name=‘Microsoft-Windows-IIS-W3SVC-WP’] and (EventID=2293)]]
WAS detected invalid configuration data
Property
Value
Severity
1
Enabled
True
AutoMitigate
True
EvaluationFrequency
PT15M
WindowSize
PT15M
Type
rows
Query
Event | where EventID in (5174,5179,5180) and EventLog == ‘System’ and Source == ‘Microsoft-Windows-WAS’
Threshold
N/A
xPathQuery
Application!*[System[Provider[@Name=‘Microsoft-Windows-IIS-W3SVC-WP’] and (EventID=2295)]]