# Custom IIS logs into Logstash

**URL:** <https://discuss.elastic.co/t/custom-iis-logs-into-logstash/238726>\
**Category:** Logstash\
**Created:** [June 25, 2020, 4:38pm UTC](https://discuss.elastic.co/t/custom-iis-logs-into-logstash/238726 "2020-06-25T16:38:45Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![andrew.campbell](https://avatars.discourse-cdn.com/v4/letter/a/13edae/32.png) [@andrew.campbell](https://discuss.elastic.co/u/andrew.campbell)\
**Post date:** [June 25, 2020, 4:38pm UTC](https://discuss.elastic.co/t/custom-iis-logs-into-logstash/238726/1 "2020-06-25T16:38:45Z")

</div>

I've installed the stack on a Windows machine to be able to index and visualize IIS logs. Our logs have a custom field from the header and additional fields not in the standard W3C IIS log format. I'm trying to map the fields to get Logstash to ingest them, but I'm getting an error saying to "check that fields match your IIS log settings". I'm expecting that my input file type of "iis\_log\_1" is incorrect for this application since the fields do not match the standard format. What I haven't been able to find is what file type I should be using to get this to work. This is my current conf file:

```
# Sample Logstash configuration for creating a simple

input {
  file {
type => "iis_log_1"
path => "E:\PROD_IIS_LOGS\bothHosts\202004\8.2-refid1-iislogs-04/u_ex200423_x.log"
start_position => "beginning"
  }
}

filter {
  if [type] == "iis_log_1" {
	  #ignore log comments
	  if [message] =~ "^#" {
		drop {}
	  }
	  grok {
		# check that fields match your IIS log settings
		match => [%{TIMESTAMP_ISO8601:log_timestamp} %{WORD:computername} %{IPORHOST:site} %{WORD:method} %{URIPATH:page} %{NOTSPACE:querystring} %{NUMBER:port} %{NOTSPACE:username} %{IPORHOST:c-ip} %{NOTSPACE:useragent} %{NOTSPACE:referrer} %{IPORHOST:clienthost} %{NUMBER:scstatus} %{NUMBER:scsubstatus} %{NUMBER:winstatus} %{NUMBER:bytessent} %{NUMBER:bytesreceived} %{NUMBER:time_taken} %{IPORHOST:x-forwarded-for}]
	  }
		date {
		match => ["log_timestamp", "YYYY-MM-dd HH:mm:ss"]
		  timezone => "Etc/UTC"
	  }    
	  useragent {
		source=> "useragent"
		prefix=> "browser"
	  }
	  mutate {
		remove_field => ["log_timestamp"]
	  }
  }
}

output {
  elasticsearch {
hosts => ["http://localhost:9200"]
	index => "indexforlogstash-%{+YYYY.MM.dd}"
  }
}
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 25, 2020, 4:53pm UTC](https://discuss.elastic.co/t/custom-iis-logs-into-logstash/238726/2 "2020-06-25T16:53:57Z")

</div>

> [@andrew.campbell](#):
>
> ```auto
> grok {
> # check that fields match your IIS log settings
> match => [%{TIMESTAMP_ISO8601:log_timestamp} %{WORD:computername} %{IPORHOST:site} %{WORD:method} %{URIPATH:page} %{NOTSPACE:querystring} %{NUMBER:port} %{NOTSPACE:username} %{IPORHOST:c-ip} %{NOTSPACE:useragent} %{NOTSPACE:referrer} %{IPORHOST:clienthost} %{NUMBER:scstatus} %{NUMBER:scsubstatus} %{NUMBER:winstatus} %{NUMBER:bytessent} %{NUMBER:bytesreceived} %{NUMBER:time_taken} %{IPORHOST:x-forwarded-for}]
> }
> 
> ```

That should be causing an error. The syntax for grok is

```
grok {
    match => { "message" => "%{TIMESTAMP_ISO8601:log_timestamp} ..." }
}

```

Also, do not use backslash in the path option of a file input, it is treated as an escape, use forward slash.

---

<div class="post-metadata">

**Author:** ![andrew.campbell](https://avatars.discourse-cdn.com/v4/letter/a/13edae/32.png) [@andrew.campbell](https://discuss.elastic.co/u/andrew.campbell)\
**Post date:** [June 25, 2020, 7:51pm UTC](https://discuss.elastic.co/t/custom-iis-logs-into-logstash/238726/3 "2020-06-25T19:51:16Z")

</div>

Thanks, Badger!

What ultimately worked was this:

match =\> ["message", "%{TIMESTAMP\_ISO8601:log\_timestamp} %{WORD:computername} %{IPORHOST:site} %{WORD:method} %{URIPATH:page} %{NOTSPACE:querystring} %{NUMBER:port} %{NOTSPACE:username} %{IPORHOST:c-ip} %{NOTSPACE:useragent} %{NOTSPACE:referrer} %{IPORHOST:clienthost} %{NUMBER:scstatus} %{NUMBER:scsubstatus} %{NUMBER:winstatus} %{NUMBER:bytessent} %{NUMBER:bytesreceived} %{NUMBER:time\_taken} %{IPORHOST:x-forwarded-for}"]

["message", "%{TIMESTAMP..."]

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 23, 2020, 7:51pm UTC](https://discuss.elastic.co/t/custom-iis-logs-into-logstash/238726/4 "2020-07-23T19:51:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
