# Custom IIS logs into Logstash

**URL:** <https://discuss.elastic.co/t/custom-iis-logs-into-logstash/238726>\
**Category:** Logstash\
**Created:** [June 25, 2020, 4:38pm UTC](https://discuss.elastic.co/t/custom-iis-logs-into-logstash/238726 "2020-06-25T16:38:45Z")\
**Posts on this page:** 1\
**Showing post:** 3

<div class="post-metadata">

**Author:** ![andrew.campbell](https://avatars.discourse-cdn.com/v4/letter/a/13edae/32.png) [@andrew.campbell](https://discuss.elastic.co/u/andrew.campbell)\
**Post date:** [June 25, 2020, 7:51pm UTC](https://discuss.elastic.co/t/custom-iis-logs-into-logstash/238726/3 "2020-06-25T19:51:16Z")

</div>

Thanks, Badger!

What ultimately worked was this:

match =\> ["message", "%{TIMESTAMP\_ISO8601:log\_timestamp} %{WORD:computername} %{IPORHOST:site} %{WORD:method} %{URIPATH:page} %{NOTSPACE:querystring} %{NUMBER:port} %{NOTSPACE:username} %{IPORHOST:c-ip} %{NOTSPACE:useragent} %{NOTSPACE:referrer} %{IPORHOST:clienthost} %{NUMBER:scstatus} %{NUMBER:scsubstatus} %{NUMBER:winstatus} %{NUMBER:bytessent} %{NUMBER:bytesreceived} %{NUMBER:time\_taken} %{IPORHOST:x-forwarded-for}"]

["message", "%{TIMESTAMP..."]

---

_[View the full topic](https://discuss.elastic.co/t/custom-iis-logs-into-logstash/238726)._
