# Exclude Lines containing specific string from IIS Logs

**URL:** <https://discuss.elastic.co/t/exclude-lines-containing-specific-string-from-iis-logs/173464>\
**Category:** Logstash\
**Created:** [March 22, 2019, 9:39am UTC](https://discuss.elastic.co/t/exclude-lines-containing-specific-string-from-iis-logs/173464 "2019-03-22T09:39:05Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![nyarlath](https://avatars.discourse-cdn.com/v4/letter/n/94ad74/32.png) [@nyarlath](https://discuss.elastic.co/u/nyarlath)\
**Post date:** [March 22, 2019, 9:39am UTC](https://discuss.elastic.co/t/exclude-lines-containing-specific-string-from-iis-logs/173464/1 "2019-03-22T09:39:05Z")

</div>

Hello all,

I have a simple question, but i cannot find an answer that satisfies me.  
I am sending IIS 7.5 logs to logstash, but we have a monitoring tool that is doing a healthcheck every minute.  
The message line is like this :

`2019-03-22 09:32:21 W3SVC2 DEV-SERVER-001 10.0.143.17 GET /health-monitoring - 80 - 10.0.143.12 HTTP/1.1 - - - www.dev-site.com 200 0 0 274 81 15`

so it gives :

![image](https://us1.discourse-cdn.com/elastic/original/3X/3/c/3cda971d9f6c5ad3fbbaefbf376313f82e9e2a43.png)

And I don't want the lines containing the word "health" to be sent, because they are pointless to me, and polluting my views and my index.

I tried on filebeat side to add this :  
`exclude_lines: ['.*health.*']`

in the iis.yml file, but still they are sent.

Oh, and this is my logstash config file :

```
input {
 beats {
  port => 5044
  #type => "iis"
 }
}

filter {
  dissect {
    mapping => {
      message => '%{log_timestamp} %{+log_timestamp} %{s-sitename} %{s-computername} %{s-ip} %{cs-method} %{cs-uri-stem} %{cs-uri-query} %{s-port} %{cs-username} %{c-ip} %{cs-version} %{cs-user-agent} %{cs-cookie} %{cs-referer} %{cs-host} %{sc-status} %{sc-substatus} %{sc-win32-status} %{sc-bytes} %{cs-bytes} %{time-taken}'
    }
  }
}

output {
 elasticsearch {
    hosts => "localhost:9200"
    manage_template => false
    index => "%{[@metadata][beat]}-iis-%{+YYYY.MM.dd}"
    document_type => "%{[@metadata][type]}"
  }
 stdout { codec => rubydebug }
}

```

Thank you for your help.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 22, 2019, 1:04pm UTC](https://discuss.elastic.co/t/exclude-lines-containing-specific-string-from-iis-logs/173464/2 "2019-03-22T13:04:26Z")

</div>

```
if [cs-uri-stem] == "/health-monitoring" { drop {} }

```

or

```
if [cs-uri-stem] =~ /health/ { drop {} }
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 19, 2019, 1:04pm UTC](https://discuss.elastic.co/t/exclude-lines-containing-specific-string-from-iis-logs/173464/3 "2019-04-19T13:04:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
