# Failed to format message from \*

**URL:** <https://discuss.elastic.co/t/failed-to-format-message-from/165728>\
**Category:** Logs\
**Created:** [January 25, 2019, 8:51am UTC](https://discuss.elastic.co/t/failed-to-format-message-from/165728 "2019-01-25T08:51:01Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Code](https://avatars.discourse-cdn.com/v4/letter/c/3d9bf3/32.png) [@Code](https://discuss.elastic.co/u/Code)\
**Post date:** [January 25, 2019, 8:51am UTC](https://discuss.elastic.co/t/failed-to-format-message-from/165728/1 "2019-01-25T08:51:02Z")

</div>

![a](https://us1.discourse-cdn.com/elastic/original/3X/9/6/96f95917410c4400bb9c6301e9510c552242218a.png)

I want to see the detail from my server's IIS logs , and I found that kibana cannot format the information of IIS logs. Pls tell what measure should i do ,so I can see the logs' detail. thank you

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [January 25, 2019, 12:57pm UTC](https://discuss.elastic.co/t/failed-to-format-message-from/165728/2 "2019-01-25T12:57:22Z")

</div>

Hi @Code,

the heuristic used by the Logs UI to extract the log message attempts a few known filebeat formats and falls back to the `message` and `@message` attribute of the document. We're working on making these rules configurable.

What you're seeing indicates that the docs representing the IIS log events match neither of these rules. While we're working on improving filebeat module compatibility, you could work around this in the meantime by copying the desired fields of the log event to the `message` attribute during ingestion.

---

<div class="post-metadata">

**Author:** ![Code](https://avatars.discourse-cdn.com/v4/letter/c/3d9bf3/32.png) [@Code](https://discuss.elastic.co/u/Code)\
**Post date:** [January 28, 2019, 3:25am UTC](https://discuss.elastic.co/t/failed-to-format-message-from/165728/3 "2019-01-28T03:25:07Z")

</div>

Thank you, but can you tell me where is the message attribute? In other word, which .yml filed should be change?

---

<div class="post-metadata">

**Author:** ![Code](https://avatars.discourse-cdn.com/v4/letter/c/3d9bf3/32.png) [@Code](https://discuss.elastic.co/u/Code)\
**Post date:** [January 28, 2019, 3:26am UTC](https://discuss.elastic.co/t/failed-to-format-message-from/165728/4 "2019-01-28T03:26:17Z")

</div>

My OS is Windows Server 2012

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [January 28, 2019, 11:28am UTC](https://discuss.elastic.co/t/failed-to-format-message-from/165728/5 "2019-01-28T11:28:13Z")

</div>

What I wanted to express is that the message attribute is not properly configurable at the moment. As a workaround I would recommend to make sure a `message` field is created on each doc during ingestion.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 25, 2019, 11:28am UTC](https://discuss.elastic.co/t/failed-to-format-message-from/165728/6 "2019-02-25T11:28:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
