Three of our intranet IIS servers are behind F5 Load Balancer. I grabbed the W3c log from one of the servers for a typical day, and there turned out to be about 100k entries.
What I feel uneasy is the number of occurrences of half-complete entries.
Our servers use Windows Authentication, but out of 100k entries, nearly 70k of them are missing cs-username (the cs-uri-stem of which are just 1 single slash '/').
The servers mainly attends to requests to a Content Management System hooked up to IIS by ISAPI. Does this have anything to do with the large amount of "weird" log entries? And is this something I should be concerned about?