# Add custom field on IIS log

**URL:** <https://discuss.elastic.co/t/add-custom-field-on-iis-log/256054>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [November 20, 2020, 2:34am UTC](https://discuss.elastic.co/t/add-custom-field-on-iis-log/256054 "2020-11-20T02:34:52Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![victortamotsu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/victortamotsu/32/79355_2.png) [@victortamotsu](https://discuss.elastic.co/u/victortamotsu)\
**Post date:** [November 20, 2020, 2:34am UTC](https://discuss.elastic.co/t/add-custom-field-on-iis-log/256054/1 "2020-11-20T02:34:52Z")

</div>

Hi everybody!  
I added a custom field on IIS log to register the original client IP (x-forwarded-for). This is necessary because I use a reverse proxy to publish my webserver, so the Client IP Address (c-ip) show only the reverse proxy IP.  
How can I send this new field in Elasticsearch? I use Filebeat to read me IIS logs; how to add this custom field?  
Here is the new header of IIS log file after I added the custom field and two lines of the generated log:

> #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken **ClientIpHeader**  
> _2020-11-19 23:59:42 10.22.1.6 POST /cpv/xxxx.svc - 80 - 10.21.0.4 Mozilla/4.0+(compatible;+Cache;) - 200 0 0 56 177.184.206.230:59817_  
> _2020-11-19 23:59:42 10.22.1.6 POST /bgn/xxxx.svc - 80 - 10.21.0.4 Mozilla/4.0+(compatible;+Cache;) [https://yyyyy.com:443/xxx/xxxx.svc](https://yyyyy.com:443/xxx/xxxx.svc) 200 0 0 38 187.72.8.165:53602_

I will apreciate any help!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 18, 2020, 4:34am UTC](https://discuss.elastic.co/t/add-custom-field-on-iis-log/256054/2 "2020-12-18T04:34:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
