-
Notifications
You must be signed in to change notification settings - Fork 0
IIS
Internet Information Services diagnostics: worker processes, app pool history, log parsing/tailing, failed request tracing, and certificate bindings. Requires WebAdministration/IISAdministration.
9 function(s) in Public/iis/.
-
Get-IISAppPoolHistory— Reconstructs the lifecycle history (recycles, rapid-fail shutdowns, crashes, start/stop, identity changes) of IIS application pools from Windows event logs. -
Get-IISCertificateBinding— Inventories every IIS HTTPS binding joined to the X509 certificate it actually presents. -
Get-IISCurrentRequest— Lists HTTP requests currently executing in IIS (typed equivalent ofappcmd list requests). -
Get-IISFailedRequestTrace— Parses IIS Failed Request Tracing (FREB) fr######.xml files into typed PSWinOps.IISFailedRequestTrace objects. -
Get-IISParsedLog— Parses IIS W3C extended log files into structured PSWinOps.IISLogEntry objects with streaming, header re-detection, and optional filtering. -
Get-IISWorkerProcess— Inventories IIS worker processes (w3wp.exe) enriched with app pool, sites, identity, and resource metrics. -
Set-IISBindingCertificate— Replaces the SSL/TLS certificate on one or more IIS https site bindings. -
Test-IISBindingCertificate— Validates each IIS HTTPS binding certificate and emits a per-binding verdict (expiration, chain, hostname, key, store). -
Watch-IISLog— Streams new entries from a live IIS site log in real time (tail -f), parsing each line into a PSWinOps.IISLogEntry object as it is written.
Reconstructs the lifecycle history (recycles, rapid-fail shutdowns, crashes, start/stop, identity changes) of IIS application pools from Windows event logs.
Mines the System (Microsoft-Windows-WAS), Application (W3SVC-WP, WAS) and optionally the Microsoft-Windows-IIS-W3SVC-WP/Operational event logs on one or more servers, then classifies every relevant entry into a typed event object enriched with the owning application pool, worker PID and a normalised reason code. Provides the operational timeline IISAdministration does not expose, with server-side filtering via Get-WinEvent -FilterHashtable for performance.
Syntax
Get-IISAppPoolHistory [-ComputerName <string[]>] [-AppPoolName <string[]>] [-After <datetime>] [-Before <datetime>] [-Category <string[]>] [-EventId <int[]>] [-IncludeOperationalLog] [-MaxEvents <int>] [-Tail <int>]Examples
Get-IISAppPoolHistory -After (Get-Date).AddHours(-24) -Category Recycle,RapidFailReturns all recycle and rapid-fail events from the last 24 hours on the local machine.
'WEB01','WEB02' | Get-IISAppPoolHistory -AppPoolName 'api-*' -Tail 20Returns the 20 most recent history events for application pools matching 'api-*' across two web servers.
Get-IISHealth -ComputerName WEB01 | Get-IISAppPoolHistory -After (Get-Date).AddDays(-7)Pipeline from Get-IISHealth to retrieve a week of app pool history.
Get-IISAppPoolHistory -ComputerName WEB01 -Category Crash -IncludeOperationalLog -After (Get-Date).AddDays(-1)Includes the admin Operational channel for additional ISAPI / FastCGI crash detail over the last 24 hours.
Output: PSWinOps.IISAppPoolHistoryEvent
Inventories every IIS HTTPS binding joined to the X509 certificate it actually presents.
Enumerates all https bindings on one or more IIS hosts and joins each binding to the X509 certificate it points at, surfacing site, ip:port:hostheader, SNI/CCS flags, thumbprint, subject, SAN, issuer, validity window, days until expiration, certificate store of record and presence of the private key. Provides the read-only typed counterpart of Set-IISBindingCertificate that IISAdministration does not expose in a single cmdlet. Falls back gracefully from WebAdministration to IISAdministration to appcmd, and pipes cleanly into Set-IISBindingCertificate for rotation workflows.
Syntax
Get-IISCertificateBinding [-ComputerName <string[]>] [-SiteName <string[]>] [-Thumbprint <string[]>] [-HostHeader <string[]>] [-Port <int[]>] [-ExpiringInDays <int>] [-IncludeExpired]Examples
Get-IISCertificateBindingInventories all https bindings and their certificates on the local machine.
'WEB01','WEB02','WEB03' | Get-IISCertificateBinding -Credential (Get-Credential)Audits certificate bindings across a web farm using alternate credentials.
Get-IISCertificateBinding -ComputerName WEB01 -ExpiringInDays 30Returns bindings whose certificate expires within the next 30 days.
Get-IISCertificateBinding -SiteName 'www*' -HostHeader '*.contoso.com'Filters by site name wildcard and host header wildcard.
Get-IISCertificateBinding -ComputerName WEB01 -ExpiringInDays 15 | Set-IISBindingCertificate -Thumbprint $newTp -Confirm:$falsePipes expiring bindings directly into the rotation cmdlet.
Get-IISCertificateBinding | Where-Object Status -eq 'CertNotFound'Surfaces orphan bindings whose certificate has been removed from the store.
Output: PSWinOps.IISCertificateBinding
Lists HTTP requests currently executing in IIS (typed equivalent of appcmd list requests).
Enumerates every request actively being processed by IIS worker processes
on one or more target servers, joining each entry with the owning
application pool, the served site, the absolute URL, HTTP verb, client IP,
elapsed time and pipeline state. Provides real-time visibility on stuck or
long-running requests -- diagnostic data that the IISAdministration module
does not expose. Implementation parses appcmd.exe list requests /xml
inside a remoting-aware scriptblock dispatched through Invoke-RemoteOrLocal.
Syntax
Get-IISCurrentRequest [-ComputerName <string[]>] [-AppPoolName <string[]>] [-SiteName <string[]>] [-MinElapsedMs <int>]Examples
Get-IISCurrentRequestReturns all in-flight HTTP requests on the local IIS instance.
Get-IISCurrentRequest -ComputerName 'WEB01'Returns in-flight requests from a single remote server.
'WEB01','WEB02' | Get-IISCurrentRequest -Credential (Get-Credential)Queries multiple remote servers via pipeline with alternate credentials.
Get-IISCurrentRequest -MinElapsedMs 5000 | Sort-Object TimeElapsedMs -DescendingSurfaces stuck requests running for more than 5 seconds, sorted by elapsed time.
Get-IISCurrentRequest -SiteName 'www.contoso.com' -AppPoolName 'API*'Filters in-flight requests to a specific site and application pool pattern.
Output: PSWinOps.IISCurrentRequest
Parses IIS Failed Request Tracing (FREB) fr######.xml files into typed PSWinOps.IISFailedRequestTrace objects.
Streams IIS Failed Request Tracing trace files and emits one structured object per fr######.xml. Auto-resolves the FREB folder per site via WebAdministration / IISAdministration / appcmd fallback, parses the root attributes (URL, verb, statusCode, timeTaken, appPool, worker PID, failureReason) and surfaces the first error/warning event (module, notification, message) without requiring a DOM load. Supports multi-host execution via WinRM, per-site folder override, -After/-Before/-StatusCode/-FailureReason filters, -Tail for the most recent N traces, and -IncludeEvents to attach the full event timeline.
Syntax
Get-IISFailedRequestTrace [-ComputerName <string[]>] [-SiteName <string[]>] [-SiteId <int[]>] [-Path <string[]>] [-StatusCode <int[]>] [-FailureReason <string[]>] [-After <datetime>] [-Before <datetime>] [-Tail <int>] [-IncludeEvents]Examples
Get-IISFailedRequestTraceReturns all FREB trace files on the local server as PSWinOps.IISFailedRequestTrace objects.
Get-IISFailedRequestTrace -ComputerName WEB01 -SiteName 'Default Web Site' -Tail 20Returns the last 20 failures for a specific site on a remote host.
Get-IISFailedRequestTrace -ComputerName WEB01,WEB02 -StatusCode 500,502,503,504 -After (Get-Date).AddHours(-1)Returns all 500-class failures from the last hour, across multiple servers.
Get-IISFailedRequestTrace -SiteName 'api' -Tail 1 -IncludeEvents | Select-Object -ExpandProperty EventsDrills into a specific failure including its full event timeline.
Output: PSWinOps.IISFailedRequestTrace
Parses IIS W3C extended log files into structured PSWinOps.IISLogEntry objects with streaming, header re-detection, and optional filtering.
Streams one or more IIS W3C extended log files and emits one PSWinOps.IISLogEntry object per data line. The parser honours the #Fields directive (including mid-file changes after a log restart), normalises IIS "-" placeholders to $null, decodes the "+" space encoding used by IIS for User-Agent and Referer, and parses date+time into a UTC DateTime. Filtering parameters (-After/-Before/-Method/ -Status/-UriLike/-ClientIP/-Tail) are applied during streaming so very large logs do not need to fit in memory.
Syntax
Get-IISParsedLog -Path <string[]> -LiteralPath <string[]> [-After <datetime>] [-Before <datetime>] [-Method <string[]>] [-Status <int[]>] [-UriLike <string>] [-ClientIP <string[]>] [-Tail <int>] [-Encoding <string>]Examples
Get-IISParsedLog -Path C:\inetpub\logs\LogFiles\W3SVC1\u_ex260514.logStreams all entries from a single IIS log file as PSWinOps.IISLogEntry objects.
Get-ChildItem C:\inetpub\logs\LogFiles -Recurse -Filter u_ex*.log |
Get-IISParsedLog -After (Get-Date).AddHours(-1) -Status 500,502,503,504Streams all 5xx entries from the last hour across all IIS sites.
Get-IISParsedLog -Path .\u_ex260514.log -Method POST -UriLike '/api/*' |
Where-Object TimeTaken -gt 2000Finds slow POST requests to the /api/* URI path.
Get-IISParsedLog -Path .\u_ex260514.log -ClientIP 10.0.0.42 -Tail 100Returns the last 100 matching entries from a specific client IP address.
Output: PSWinOps.IISLogEntry
One object per parsed data line. Properties absent from the active #Fields directive are emitted as $null.
Inventories IIS worker processes (w3wp.exe) enriched with app pool, sites, identity, and resource metrics.
Enumerates every w3wp.exe process on one or more target servers and joins it with IIS configuration so each row carries the owning application pool, the sites and applications it serves, its identity, PID, uptime, CPU time, memory footprint (working set / private / virtual), thread count and handle count. Provides the operational overview that the native IISAdministration module does not expose in a single cmdlet. Falls back gracefully from WebAdministration to IISAdministration to appcmd/CIM when modules are missing, and from Get-Process to CIM Win32_Process when needed.
Syntax
Get-IISWorkerProcess [-ComputerName <string[]>] [-AppPoolName <string[]>] [-ProcessId <int[]>]Examples
Get-IISWorkerProcessReturns all running w3wp.exe processes on the local machine enriched with app pool, site, identity and resource data.
Get-IISWorkerProcess -ComputerName 'WEB01'Returns IIS worker process inventory from a single remote server.
'WEB01','WEB02' | Get-IISWorkerProcess -Credential (Get-Credential)Queries multiple remote servers via pipeline with alternate credentials.
Get-IISWorkerProcess -AppPoolName 'DefaultAppPool','API*'Returns only worker processes belonging to DefaultAppPool or any pool whose name matches API*.
Get-IISWorkerProcess | Sort-Object WorkingSetMB -Descending | Select-Object -First 5Returns the top 5 worker processes by working set memory.
Output: PSWinOps.IISWorkerProcess
Replaces the SSL/TLS certificate on one or more IIS https site bindings.
Replace the SSL/TLS certificate bound to one or more IIS HTTPS site bindings, typically to rotate a certificate that is approaching expiration. The new certificate must already exist in the target certificate store (LocalMachine\My by default). The function is idempotent: running it twice with the same thumbprint yields Status=AlreadyUpToDate on the second call. Supports remote execution via WinRM, -WhatIf/-Confirm (ConfirmImpact=High), and pipeline input by property name from Get-IISHealth / Get-SSLCertificate.
Syntax
Set-IISBindingCertificate [-ComputerName <string[]>] -SiteName <string> [-BindingInformation <string>] -Thumbprint <string> [-CertStoreLocation <string>] [-Force]Examples
Set-IISBindingCertificate -SiteName 'www.contoso.com' -Thumbprint 'A1B2C3D4E5F6A1B2C3D4E5F6A1B2C3D4E5F6A1B2' -Confirm:$falseReplaces the cert on every https binding of the site without prompting.
Set-IISBindingCertificate -SiteName 'Default Web Site' -BindingInformation '*:443:portal.contoso.com' -Thumbprint $newTpTargets one specific binding by its ip:port:hostheader selector.
'WEB01','WEB02','WEB03' | Set-IISBindingCertificate -SiteName 'api' -Thumbprint $newTp -Credential (Get-Credential) -WhatIfPreviews certificate rotation across a fleet via pipeline with explicit credentials.
Get-SSLCertificate -ComputerName WEB01 -Port 443 | Set-IISBindingCertificate -SiteName 'www' -Thumbprint $newTpPipeline-by-property-name from Get-SSLCertificate.
Output: PSWinOps.IISBindingCertificateResult
Returns one object per (ComputerName, binding) pair.
Validates each IIS HTTPS binding certificate and emits a per-binding verdict (expiration, chain, hostname, key, store).
Inspects every https binding on one or more IIS hosts and evaluates the associated X509 certificate across six independent checks: expiration against configurable Warning/Critical thresholds, X509Chain.Build() validity, hostname/SAN match against the binding host header, private key availability, signature/key-algorithm strength, and alignment between the binding's declared CertStoreName and the store where the certificate is actually found. Each check contributes to a per-binding OverallStatus (Pass/Warning/Critical/Fail) and a Findings array describing every non-Pass condition. Complements Get-IISCertificateBinding (inventory) with an actionable verdict that IISAdministration does not expose. Falls back gracefully WebAdministration -> IISAdministration -> appcmd, supports multi-host execution via Invoke-RemoteOrLocal, and pipes cleanly from Get-IISCertificateBinding / Get-IISHealth.
Syntax
Test-IISBindingCertificate [-ComputerName <string[]>] [-SiteName <string[]>] [-BindingInformation <string[]>] [-HostHeader <string[]>] [-Thumbprint <string[]>] [-WarningDays <int>] [-CriticalDays <int>] [-MinKeySize <int>] [-SkipChainValidation] [-AllowSelfSigned] [-IncludeRevocationCheck]Examples
Test-IISBindingCertificateAudit every HTTPS binding on the local host with default thresholds.
'WEB01','WEB02','WEB03' | Test-IISBindingCertificate -Credential (Get-Credential)Audit a web farm using alternate credentials.
Test-IISBindingCertificate -ComputerName WEB01 | Where-Object OverallStatus -ne 'Pass'Surface only actionable verdicts.
Test-IISBindingCertificate -ComputerName WEB01 -WarningDays 60 -CriticalDays 14Tighten the expiration window for a renewal sweep.
Test-IISBindingCertificate -ComputerName WEB01 -SkipChainValidationSkip chain build on an offline / air-gapped host.
Get-IISCertificateBinding -ComputerName WEB01 -SiteName www | Test-IISBindingCertificateRe-test a specific binding piped from the inventory cmdlet.
Test-IISBindingCertificate -ComputerName WEB01 -IncludeRevocationCheckEnable online revocation (CRL/OCSP) for a compliance run.
Output: PSWinOps.IISCertificateBindingTestResult
Streams new entries from a live IIS site log in real time (tail -f), parsing each line into a PSWinOps.IISLogEntry object as it is written.
Resolves the active W3C log file of a given IIS site from its configuration (WebAdministration provider, falling back to Microsoft.Web.Administration or appcmd.exe), opens it with FileShare.ReadWrite|Delete so as not to disturb IIS, and emits each new data line as a structured PSWinOps.IISLogEntry, the same shape produced by Get-IISParsedLog. Honours mid-file #Fields re-detection (post-recycle) and optionally follows daily log rollover via -FollowRollover. Filtering parameters (-Method/-Status/-UriLike/-ClientIP/ -MinStatus) are applied during streaming. Use -InitialLines to replay the last N entries before entering follow mode, and -Duration/-MaxEntries to bound a run (recommended for remote sessions).
Syntax
Watch-IISLog [-ComputerName <string[]>] -SiteName <string> [-LogFormat <string>] [-InitialLines <int>] [-FollowRollover] [-PollIntervalMs <int>] [-Duration <timespan>] [-MaxEntries <int>] [-Method <string[]>] [-Status <int[]>] [-UriLike <string>] [-ClientIP <string[]>] [-MinStatus <int>]Examples
Watch-IISLog -SiteName 'Default Web Site'Tails the Default Web Site log in real time, emitting parsed entries.
Watch-IISLog -SiteName 'Default Web Site' -InitialLines 50 -MinStatus 400Replays the last 50 error-or-worse entries then follows for new ones.
Watch-IISLog -SiteName 'www.contoso.com' -FollowRollover -Duration (New-TimeSpan -Hours 1)Follows the site log including daily rollover for one hour.
'WEB01' | Watch-IISLog -SiteName 'api' -Credential (Get-Credential) -MaxEntries 1000Remote tail with credentials, capped at 1000 entries.
Watch-IISLog -SiteName 'api' -Method POST -UriLike '/api/*' | Where-Object TimeTaken -gt 2000Streams slow POST requests to the /api/* path in real time.
Output: PSWinOps.IISLogEntry
One object per parsed data line. Properties absent from the active #Fields directive are emitted as $null.
Domains
- Active Directory (22)
- Certificate (1)
- Event Log (9)
- Health Check (16)
- IIS (9)
- Network (26)
- NTP (5)
- Proxy (4)
- RDP (6)
- Security (1)
- System (20)
- Utils (4)
- VSS (Shadow Copy) (6)
- Windows Update (10)