Duplicate Field with grok parsing iis logs

hello all

i am mount my iis logs to ELK centos machine
i am using logstash for parsing the iislogs

but when i looking iis logs in kibana i saw grok field as duplicate
message is o.k

kindly your adive

thx
asaf

Please supply

  • your configuration,
  • an example of an input line that Logstash parses, and
  • an example of an event with a duplicate field (no Kibana screenshot please).