# Add new additional field from IIS log

**URL:** <https://discuss.elastic.co/t/add-new-additional-field-from-iis-log/230859>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 3, 2020, 10:18am UTC](https://discuss.elastic.co/t/add-new-additional-field-from-iis-log/230859 "2020-05-03T10:18:06Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![coopx](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/coopx/32/67580_2.png) [@coopx](https://discuss.elastic.co/u/coopx)\
**Post date:** [May 3, 2020, 10:18am UTC](https://discuss.elastic.co/t/add-new-additional-field-from-iis-log/230859/1 "2020-05-03T10:18:06Z")

</div>

Hi,

I am hoping someone can help me out, I am new to elastic and am testing the [Elastic.co](http://Elastic.co) hosted service.

I have an IIS log that has an additional field at the end, which is an IP address (in bold).

2020-03-31 09:32:58 10.1.1.1 GET /test - 443 - 10.1.1.1 HTTP/1.1 Mozilla/5.0+(X11;+Linux+x86\_64;+rv:45.0)+Gecko/20100101+Firefox/45.0 - [test.domain.com](http://test.domain.com) 200 0 0 49803 663 359 **4.4.4.4**

I have updated the IIS module `default.json` file located at `C:\dir\module\iis\access\ingest` to include a grok pattern to pick up the new IP address field `%{IPORHOST:iis.access.userip}`, I tested this in the grok debugger and it parses the IP in to a field called `userip`.

The log file has now been ingested and is searchable in Kibana, but I can not see the additional field. After looking at a lot of documentation I can see that I likely need to update the index, but my lack of knowledge has made this confusing.

Any help would be greatly appreciated!

Jay

---

<div class="post-metadata">

**Author:** ![ChrsMark](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrsmark/32/55858_2.png) [@ChrsMark](https://discuss.elastic.co/u/ChrsMark)\
**Post date:** [May 4, 2020, 11:41am UTC](https://discuss.elastic.co/t/add-new-additional-field-from-iis-log/230859/2 "2020-05-04T11:41:24Z")

</div>

Hi @coopx!

In order to update indexes, mappings etc you need sth like this: [https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-template.html](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-template.html)

Beyond this, I don't think that just by adding this extra parsing part will be able to work out of the box. Fields are documented and defined so as to apply to the field mappings accordingly. See: [https://github.com/elastic/beats/blob/master/filebeat/module/iis/access/\_meta/fields.yml](https://github.com/elastic/beats/blob/master/filebeat/module/iis/access/_meta/fields.yml). This makes your approach quite hacky :), which is ok but you have to deal with all these internal stuff.

Since you just want this extra field I would suggest you checking [`script_processor`](https://www.elastic.co/guide/en/beats/filebeat/master/processor-script.html) and try to extract the extra field from the original message.

---

<div class="post-metadata">

**Author:** ![coopx](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/coopx/32/67580_2.png) [@coopx](https://discuss.elastic.co/u/coopx)\
**Post date:** [May 4, 2020, 12:25pm UTC](https://discuss.elastic.co/t/add-new-additional-field-from-iis-log/230859/3 "2020-05-04T12:25:31Z")

</div>

Thanks so much @ChrsMark for taking the time to reply.

This is exactly the help I needed, it looks like the [script\_processor](https://www.elastic.co/guide/en/beats/filebeat/master/processor-script.html) will do the job.

Have a great day, I'll update this thread with the solution once I have it sorted on the off chance it helps someone else.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 1, 2020, 12:33pm UTC](https://discuss.elastic.co/t/add-new-additional-field-from-iis-log/230859/4 "2020-06-01T12:33:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
