# Error on the Logs page in Kibana on Elastic cloud hosted on AWS

**URL:** <https://discuss.elastic.co/t/error-on-the-logs-page-in-kibana-on-elastic-cloud-hosted-on-aws/169261>\
**Category:** Logs\
**Created:** [February 20, 2019, 4:46pm UTC](https://discuss.elastic.co/t/error-on-the-logs-page-in-kibana-on-elastic-cloud-hosted-on-aws/169261 "2019-02-20T16:46:14Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![ajazam1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ajazam1/32/38237_2.png) [@ajazam1](https://discuss.elastic.co/u/ajazam1)\
**Post date:** [February 20, 2019, 4:46pm UTC](https://discuss.elastic.co/t/error-on-the-logs-page-in-kibana-on-elastic-cloud-hosted-on-aws/169261/1 "2019-02-20T16:46:14Z")

</div>

We are using the Elastic Cloud hosted solution on AWS at version 6.6.1. We are using filebeats 6.6.0 and the IIS module to parse IIS 10 logs into Elastic Search.

When we look at the logs page we are seeing many

**failed to format message from c:\inetpub\logs\Logfiles\W3SVC3\u\_ex190220.log**

lines. This error appears at [https://github.com/elastic/kibana/blob/master/x-pack/plugins/infra/server/lib/domains/log\_entries\_domain/builtin\_rules/index.ts](https://github.com/elastic/kibana/blob/master/x-pack/plugins/infra/server/lib/domains/log_entries_domain/builtin_rules/index.ts) in the source code. My typescript isn't good enough for me to trace the problem.

Does anybody know if we are doing anything wrong or is there a bug in Kibana?

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [February 20, 2019, 6:17pm UTC](https://discuss.elastic.co/t/error-on-the-logs-page-in-kibana-on-elastic-cloud-hosted-on-aws/169261/2 "2019-02-20T18:17:28Z")

</div>

Hi @ajazam1,

the message you're seeing stems from the fact that the Logs UI didn't properly support the docs created by filebeat's IIS module. This has been fixed in [Kibana issue #30398](https://github.com/elastic/kibana/pull/30398) and will be part of the 6.7 release of the Elastic stack.

If you are looking for a quick workaround until then, you could adjust the ingestion pipeline to not delete the `message` field during ingestion. The pipeline should be called something like `filebeat-6.6.0-iis-access-pipeline` and can be read or written using the [ingest pipeline APIs](https://www.elastic.co/guide/en/elasticsearch/reference/current/ingest-apis.html).

Please let me know if you require more assistance with that. I apologize for the inconvenience this has caused.

---

<div class="post-metadata">

**Author:** ![ajazam](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ajazam/32/3457_2.png) [@ajazam](https://discuss.elastic.co/u/ajazam)\
**Post date:** [February 21, 2019, 9:26am UTC](https://discuss.elastic.co/t/error-on-the-logs-page-in-kibana-on-elastic-cloud-hosted-on-aws/169261/3 "2019-02-21T09:26:06Z")

</div>

Thank you. I think I will wait for the next version of Elastic Stack.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 21, 2019, 9:26am UTC](https://discuss.elastic.co/t/error-on-the-logs-page-in-kibana-on-elastic-cloud-hosted-on-aws/169261/4 "2019-03-21T09:26:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
