Skip to content
Franck SALLET edited this page Sep 5, 2026 · 1 revision

IIS

Internet Information Services diagnostics: worker processes, app pool history, log parsing/tailing, failed request tracing, and certificate bindings. Requires WebAdministration/IISAdministration.

9 function(s) in Public/iis/.

Functions

  • Get-IISAppPoolHistory — Reconstructs the lifecycle history (recycles, rapid-fail shutdowns, crashes, start/stop, identity changes) of IIS application pools from Windows event logs.
  • Get-IISCertificateBinding — Inventories every IIS HTTPS binding joined to the X509 certificate it actually presents.
  • Get-IISCurrentRequest — Lists HTTP requests currently executing in IIS (typed equivalent of appcmd list requests).
  • Get-IISFailedRequestTrace — Parses IIS Failed Request Tracing (FREB) fr######.xml files into typed PSWinOps.IISFailedRequestTrace objects.
  • Get-IISParsedLog — Parses IIS W3C extended log files into structured PSWinOps.IISLogEntry objects with streaming, header re-detection, and optional filtering.
  • Get-IISWorkerProcess — Inventories IIS worker processes (w3wp.exe) enriched with app pool, sites, identity, and resource metrics.
  • Set-IISBindingCertificate — Replaces the SSL/TLS certificate on one or more IIS https site bindings.
  • Test-IISBindingCertificate — Validates each IIS HTTPS binding certificate and emits a per-binding verdict (expiration, chain, hostname, key, store).
  • Watch-IISLog — Streams new entries from a live IIS site log in real time (tail -f), parsing each line into a PSWinOps.IISLogEntry object as it is written.

Reference

Get-IISAppPoolHistory

Reconstructs the lifecycle history (recycles, rapid-fail shutdowns, crashes, start/stop, identity changes) of IIS application pools from Windows event logs.

Mines the System (Microsoft-Windows-WAS), Application (W3SVC-WP, WAS) and optionally the Microsoft-Windows-IIS-W3SVC-WP/Operational event logs on one or more servers, then classifies every relevant entry into a typed event object enriched with the owning application pool, worker PID and a normalised reason code. Provides the operational timeline IISAdministration does not expose, with server-side filtering via Get-WinEvent -FilterHashtable for performance.

Syntax

Get-IISAppPoolHistory [-ComputerName <string[]>] [-AppPoolName <string[]>] [-After <datetime>] [-Before <datetime>] [-Category <string[]>] [-EventId <int[]>] [-IncludeOperationalLog] [-MaxEvents <int>] [-Tail <int>]

Examples

Get-IISAppPoolHistory -After (Get-Date).AddHours(-24) -Category Recycle,RapidFail

Returns all recycle and rapid-fail events from the last 24 hours on the local machine.

'WEB01','WEB02' | Get-IISAppPoolHistory -AppPoolName 'api-*' -Tail 20

Returns the 20 most recent history events for application pools matching 'api-*' across two web servers.

Get-IISHealth -ComputerName WEB01 | Get-IISAppPoolHistory -After (Get-Date).AddDays(-7)

Pipeline from Get-IISHealth to retrieve a week of app pool history.

Get-IISAppPoolHistory -ComputerName WEB01 -Category Crash -IncludeOperationalLog -After (Get-Date).AddDays(-1)

Includes the admin Operational channel for additional ISAPI / FastCGI crash detail over the last 24 hours.

Output: PSWinOps.IISAppPoolHistoryEvent


Get-IISCertificateBinding

Inventories every IIS HTTPS binding joined to the X509 certificate it actually presents.

Enumerates all https bindings on one or more IIS hosts and joins each binding to the X509 certificate it points at, surfacing site, ip:port:hostheader, SNI/CCS flags, thumbprint, subject, SAN, issuer, validity window, days until expiration, certificate store of record and presence of the private key. Provides the read-only typed counterpart of Set-IISBindingCertificate that IISAdministration does not expose in a single cmdlet. Falls back gracefully from WebAdministration to IISAdministration to appcmd, and pipes cleanly into Set-IISBindingCertificate for rotation workflows.

Syntax

Get-IISCertificateBinding [-ComputerName <string[]>] [-SiteName <string[]>] [-Thumbprint <string[]>] [-HostHeader <string[]>] [-Port <int[]>] [-ExpiringInDays <int>] [-IncludeExpired]

Examples

Get-IISCertificateBinding

Inventories all https bindings and their certificates on the local machine.

'WEB01','WEB02','WEB03' | Get-IISCertificateBinding -Credential (Get-Credential)

Audits certificate bindings across a web farm using alternate credentials.

Get-IISCertificateBinding -ComputerName WEB01 -ExpiringInDays 30

Returns bindings whose certificate expires within the next 30 days.

Get-IISCertificateBinding -SiteName 'www*' -HostHeader '*.contoso.com'

Filters by site name wildcard and host header wildcard.

Get-IISCertificateBinding -ComputerName WEB01 -ExpiringInDays 15 | Set-IISBindingCertificate -Thumbprint $newTp -Confirm:$false

Pipes expiring bindings directly into the rotation cmdlet.

Get-IISCertificateBinding | Where-Object Status -eq 'CertNotFound'

Surfaces orphan bindings whose certificate has been removed from the store.

Output: PSWinOps.IISCertificateBinding


Get-IISCurrentRequest

Lists HTTP requests currently executing in IIS (typed equivalent of appcmd list requests).

Enumerates every request actively being processed by IIS worker processes on one or more target servers, joining each entry with the owning application pool, the served site, the absolute URL, HTTP verb, client IP, elapsed time and pipeline state. Provides real-time visibility on stuck or long-running requests -- diagnostic data that the IISAdministration module does not expose. Implementation parses appcmd.exe list requests /xml inside a remoting-aware scriptblock dispatched through Invoke-RemoteOrLocal.

Syntax

Get-IISCurrentRequest [-ComputerName <string[]>] [-AppPoolName <string[]>] [-SiteName <string[]>] [-MinElapsedMs <int>]

Examples

Get-IISCurrentRequest

Returns all in-flight HTTP requests on the local IIS instance.

Get-IISCurrentRequest -ComputerName 'WEB01'

Returns in-flight requests from a single remote server.

'WEB01','WEB02' | Get-IISCurrentRequest -Credential (Get-Credential)

Queries multiple remote servers via pipeline with alternate credentials.

Get-IISCurrentRequest -MinElapsedMs 5000 | Sort-Object TimeElapsedMs -Descending

Surfaces stuck requests running for more than 5 seconds, sorted by elapsed time.

Get-IISCurrentRequest -SiteName 'www.contoso.com' -AppPoolName 'API*'

Filters in-flight requests to a specific site and application pool pattern.

Output: PSWinOps.IISCurrentRequest


Get-IISFailedRequestTrace

Parses IIS Failed Request Tracing (FREB) fr######.xml files into typed PSWinOps.IISFailedRequestTrace objects.

Streams IIS Failed Request Tracing trace files and emits one structured object per fr######.xml. Auto-resolves the FREB folder per site via WebAdministration / IISAdministration / appcmd fallback, parses the root attributes (URL, verb, statusCode, timeTaken, appPool, worker PID, failureReason) and surfaces the first error/warning event (module, notification, message) without requiring a DOM load. Supports multi-host execution via WinRM, per-site folder override, -After/-Before/-StatusCode/-FailureReason filters, -Tail for the most recent N traces, and -IncludeEvents to attach the full event timeline.

Syntax

Get-IISFailedRequestTrace [-ComputerName <string[]>] [-SiteName <string[]>] [-SiteId <int[]>] [-Path <string[]>] [-StatusCode <int[]>] [-FailureReason <string[]>] [-After <datetime>] [-Before <datetime>] [-Tail <int>] [-IncludeEvents]

Examples

Get-IISFailedRequestTrace

Returns all FREB trace files on the local server as PSWinOps.IISFailedRequestTrace objects.

Get-IISFailedRequestTrace -ComputerName WEB01 -SiteName 'Default Web Site' -Tail 20

Returns the last 20 failures for a specific site on a remote host.

Get-IISFailedRequestTrace -ComputerName WEB01,WEB02 -StatusCode 500,502,503,504 -After (Get-Date).AddHours(-1)

Returns all 500-class failures from the last hour, across multiple servers.

Get-IISFailedRequestTrace -SiteName 'api' -Tail 1 -IncludeEvents | Select-Object -ExpandProperty Events

Drills into a specific failure including its full event timeline.

Output: PSWinOps.IISFailedRequestTrace


Get-IISParsedLog

Parses IIS W3C extended log files into structured PSWinOps.IISLogEntry objects with streaming, header re-detection, and optional filtering.

Streams one or more IIS W3C extended log files and emits one PSWinOps.IISLogEntry object per data line. The parser honours the #Fields directive (including mid-file changes after a log restart), normalises IIS "-" placeholders to $null, decodes the "+" space encoding used by IIS for User-Agent and Referer, and parses date+time into a UTC DateTime. Filtering parameters (-After/-Before/-Method/ -Status/-UriLike/-ClientIP/-Tail) are applied during streaming so very large logs do not need to fit in memory.

Syntax

Get-IISParsedLog -Path <string[]> -LiteralPath <string[]> [-After <datetime>] [-Before <datetime>] [-Method <string[]>] [-Status <int[]>] [-UriLike <string>] [-ClientIP <string[]>] [-Tail <int>] [-Encoding <string>]

Examples

Get-IISParsedLog -Path C:\inetpub\logs\LogFiles\W3SVC1\u_ex260514.log

Streams all entries from a single IIS log file as PSWinOps.IISLogEntry objects.

Get-ChildItem C:\inetpub\logs\LogFiles -Recurse -Filter u_ex*.log |
Get-IISParsedLog -After (Get-Date).AddHours(-1) -Status 500,502,503,504

Streams all 5xx entries from the last hour across all IIS sites.

Get-IISParsedLog -Path .\u_ex260514.log -Method POST -UriLike '/api/*' |
Where-Object TimeTaken -gt 2000

Finds slow POST requests to the /api/* URI path.

Get-IISParsedLog -Path .\u_ex260514.log -ClientIP 10.0.0.42 -Tail 100

Returns the last 100 matching entries from a specific client IP address.

Output: PSWinOps.IISLogEntry

One object per parsed data line. Properties absent from the active #Fields directive are emitted as $null.


Get-IISWorkerProcess

Inventories IIS worker processes (w3wp.exe) enriched with app pool, sites, identity, and resource metrics.

Enumerates every w3wp.exe process on one or more target servers and joins it with IIS configuration so each row carries the owning application pool, the sites and applications it serves, its identity, PID, uptime, CPU time, memory footprint (working set / private / virtual), thread count and handle count. Provides the operational overview that the native IISAdministration module does not expose in a single cmdlet. Falls back gracefully from WebAdministration to IISAdministration to appcmd/CIM when modules are missing, and from Get-Process to CIM Win32_Process when needed.

Syntax

Get-IISWorkerProcess [-ComputerName <string[]>] [-AppPoolName <string[]>] [-ProcessId <int[]>]

Examples

Get-IISWorkerProcess

Returns all running w3wp.exe processes on the local machine enriched with app pool, site, identity and resource data.

Get-IISWorkerProcess -ComputerName 'WEB01'

Returns IIS worker process inventory from a single remote server.

'WEB01','WEB02' | Get-IISWorkerProcess -Credential (Get-Credential)

Queries multiple remote servers via pipeline with alternate credentials.

Get-IISWorkerProcess -AppPoolName 'DefaultAppPool','API*'

Returns only worker processes belonging to DefaultAppPool or any pool whose name matches API*.

Get-IISWorkerProcess | Sort-Object WorkingSetMB -Descending | Select-Object -First 5

Returns the top 5 worker processes by working set memory.

Output: PSWinOps.IISWorkerProcess


Set-IISBindingCertificate

Replaces the SSL/TLS certificate on one or more IIS https site bindings.

Replace the SSL/TLS certificate bound to one or more IIS HTTPS site bindings, typically to rotate a certificate that is approaching expiration. The new certificate must already exist in the target certificate store (LocalMachine\My by default). The function is idempotent: running it twice with the same thumbprint yields Status=AlreadyUpToDate on the second call. Supports remote execution via WinRM, -WhatIf/-Confirm (ConfirmImpact=High), and pipeline input by property name from Get-IISHealth / Get-SSLCertificate.

Syntax

Set-IISBindingCertificate [-ComputerName <string[]>] -SiteName <string> [-BindingInformation <string>] -Thumbprint <string> [-CertStoreLocation <string>] [-Force]

Examples

Set-IISBindingCertificate -SiteName 'www.contoso.com' -Thumbprint 'A1B2C3D4E5F6A1B2C3D4E5F6A1B2C3D4E5F6A1B2' -Confirm:$false

Replaces the cert on every https binding of the site without prompting.

Set-IISBindingCertificate -SiteName 'Default Web Site' -BindingInformation '*:443:portal.contoso.com' -Thumbprint $newTp

Targets one specific binding by its ip:port:hostheader selector.

'WEB01','WEB02','WEB03' | Set-IISBindingCertificate -SiteName 'api' -Thumbprint $newTp -Credential (Get-Credential) -WhatIf

Previews certificate rotation across a fleet via pipeline with explicit credentials.

Get-SSLCertificate -ComputerName WEB01 -Port 443 | Set-IISBindingCertificate -SiteName 'www' -Thumbprint $newTp

Pipeline-by-property-name from Get-SSLCertificate.

Output: PSWinOps.IISBindingCertificateResult

Returns one object per (ComputerName, binding) pair.


Test-IISBindingCertificate

Validates each IIS HTTPS binding certificate and emits a per-binding verdict (expiration, chain, hostname, key, store).

Inspects every https binding on one or more IIS hosts and evaluates the associated X509 certificate across six independent checks: expiration against configurable Warning/Critical thresholds, X509Chain.Build() validity, hostname/SAN match against the binding host header, private key availability, signature/key-algorithm strength, and alignment between the binding's declared CertStoreName and the store where the certificate is actually found. Each check contributes to a per-binding OverallStatus (Pass/Warning/Critical/Fail) and a Findings array describing every non-Pass condition. Complements Get-IISCertificateBinding (inventory) with an actionable verdict that IISAdministration does not expose. Falls back gracefully WebAdministration -> IISAdministration -> appcmd, supports multi-host execution via Invoke-RemoteOrLocal, and pipes cleanly from Get-IISCertificateBinding / Get-IISHealth.

Syntax

Test-IISBindingCertificate [-ComputerName <string[]>] [-SiteName <string[]>] [-BindingInformation <string[]>] [-HostHeader <string[]>] [-Thumbprint <string[]>] [-WarningDays <int>] [-CriticalDays <int>] [-MinKeySize <int>] [-SkipChainValidation] [-AllowSelfSigned] [-IncludeRevocationCheck]

Examples

Test-IISBindingCertificate

Audit every HTTPS binding on the local host with default thresholds.

'WEB01','WEB02','WEB03' | Test-IISBindingCertificate -Credential (Get-Credential)

Audit a web farm using alternate credentials.

Test-IISBindingCertificate -ComputerName WEB01 | Where-Object OverallStatus -ne 'Pass'

Surface only actionable verdicts.

Test-IISBindingCertificate -ComputerName WEB01 -WarningDays 60 -CriticalDays 14

Tighten the expiration window for a renewal sweep.

Test-IISBindingCertificate -ComputerName WEB01 -SkipChainValidation

Skip chain build on an offline / air-gapped host.

Get-IISCertificateBinding -ComputerName WEB01 -SiteName www | Test-IISBindingCertificate

Re-test a specific binding piped from the inventory cmdlet.

Test-IISBindingCertificate -ComputerName WEB01 -IncludeRevocationCheck

Enable online revocation (CRL/OCSP) for a compliance run.

Output: PSWinOps.IISCertificateBindingTestResult


Watch-IISLog

Streams new entries from a live IIS site log in real time (tail -f), parsing each line into a PSWinOps.IISLogEntry object as it is written.

Resolves the active W3C log file of a given IIS site from its configuration (WebAdministration provider, falling back to Microsoft.Web.Administration or appcmd.exe), opens it with FileShare.ReadWrite|Delete so as not to disturb IIS, and emits each new data line as a structured PSWinOps.IISLogEntry, the same shape produced by Get-IISParsedLog. Honours mid-file #Fields re-detection (post-recycle) and optionally follows daily log rollover via -FollowRollover. Filtering parameters (-Method/-Status/-UriLike/-ClientIP/ -MinStatus) are applied during streaming. Use -InitialLines to replay the last N entries before entering follow mode, and -Duration/-MaxEntries to bound a run (recommended for remote sessions).

Syntax

Watch-IISLog [-ComputerName <string[]>] -SiteName <string> [-LogFormat <string>] [-InitialLines <int>] [-FollowRollover] [-PollIntervalMs <int>] [-Duration <timespan>] [-MaxEntries <int>] [-Method <string[]>] [-Status <int[]>] [-UriLike <string>] [-ClientIP <string[]>] [-MinStatus <int>]

Examples

Watch-IISLog -SiteName 'Default Web Site'

Tails the Default Web Site log in real time, emitting parsed entries.

Watch-IISLog -SiteName 'Default Web Site' -InitialLines 50 -MinStatus 400

Replays the last 50 error-or-worse entries then follows for new ones.

Watch-IISLog -SiteName 'www.contoso.com' -FollowRollover -Duration (New-TimeSpan -Hours 1)

Follows the site log including daily rollover for one hour.

'WEB01' | Watch-IISLog -SiteName 'api' -Credential (Get-Credential) -MaxEntries 1000

Remote tail with credentials, capped at 1000 entries.

Watch-IISLog -SiteName 'api' -Method POST -UriLike '/api/*' | Where-Object TimeTaken -gt 2000

Streams slow POST requests to the /api/* path in real time.

Output: PSWinOps.IISLogEntry

One object per parsed data line. Properties absent from the active #Fields directive are emitted as $null.


PSWinOps Wiki

Home

Domains

Clone this wiki locally