# Filebeat to match IIS logs timestamp

**URL:** <https://discuss.elastic.co/t/filebeat-to-match-iis-logs-timestamp/209565>\
**Category:** Beats\
**Created:** [November 26, 2019, 6:49pm UTC](https://discuss.elastic.co/t/filebeat-to-match-iis-logs-timestamp/209565 "2019-11-26T18:49:29Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![alexserd](https://avatars.discourse-cdn.com/v4/letter/a/f17d59/32.png) [@alexserd](https://discuss.elastic.co/u/alexserd)\
**Post date:** [November 26, 2019, 6:49pm UTC](https://discuss.elastic.co/t/filebeat-to-match-iis-logs-timestamp/209565/1 "2019-11-26T18:49:29Z")

</div>

Currently @timestamp is showing as a time when logs get ingested. We need to match it with timestamp from IIS logs. Here is our ingest default.json from filebeat

{  
"description": "Pipeline for parsing IIS access logs. Requires the geoip and user\_agent plugins.",  
"processors": [  
{  
"grok": {  
"field": "message",  
"patterns": [  
"%{TIMESTAMP\_ISO8601:iis.access.time} %{IPORHOST:destination.address} %{WORD:http.request.method} %{NOTSPACE:url.path} %{NOTSPACE:url.query} %{NUMBER:destination.port:long} %{NOTSPACE:user.name} %{IPORHOST:source.address} %{NOTSPACE:user\_agent.original} %{NOTSPACE:http.request.referrer} %{NUMBER:http.response.status\_code:long} %{NUMBER:iis.access.sub\_status:long} %{NUMBER:iis.access.win32\_status:long} %{NUMBER:temp.duration:long}",  
"%{TIMESTAMP\_ISO8601:iis.access.time} %{NOTSPACE:iis.access.site\_name} %{WORD:http.request.method} %{URIPATH:url.path} %{NOTSPACE:url.query} %{NUMBER:destination.port:long} %{NOTSPACE:user.name} %{IPORHOST:source.address} %{NOTSPACE:user\_agent.original} %{NOTSPACE:iis.access.cookie} %{NOTSPACE:http.request.referrer} %{NOTSPACE:destination.domain} %{NUMBER:http.response.status\_code:long} %{NUMBER:iis.access.sub\_status:long} %{NUMBER:iis.access.win32\_status:long} %{NUMBER:http.response.body.bytes:long} %{NUMBER:http.request.body.bytes:long} %{NUMBER:temp.duration:long}",  
"%{TIMESTAMP\_ISO8601:iis.access.time} %{NOTSPACE:iis.access.site\_name} %{NOTSPACE:iis.access.server\_name} %{IPORHOST:destination.address} %{WORD:http.request.method} %{URIPATH:url.path} %{NOTSPACE:url.query} %{NUMBER:destination.port:long} %{NOTSPACE:user.name} %{IPORHOST:source.address} HTTP/%{NUMBER:http.version} %{NOTSPACE:user\_agent.original} %{NOTSPACE:iis.access.cookie} %{NOTSPACE:http.request.referrer} %{NOTSPACE:destination.domain} %{NUMBER:http.response.status\_code:long} %{NUMBER:iis.access.sub\_status:long} %{NUMBER:iis.access.win32\_status:long} %{NUMBER:http.response.body.bytes:long} %{NUMBER:http.request.body.bytes:long} %{NUMBER:temp.duration:long}",  
"%{TIMESTAMP\_ISO8601:iis.access.time} \[%{IPORHOST:destination.address}\]\(http://%{IPORHOST:destination.address}\) %{WORD:http.request.method} %{URIPATH:url.path} %{NOTSPACE:url.query} %{NUMBER:destination.port:long} %{NOTSPACE:user.name} \[%{IPORHOST:source.address}\]\(http://%{IPORHOST:source.address}\) %{NOTSPACE:user\_agent.original} %{NUMBER:http.response.status\_code:long} %{NUMBER:iis.access.sub\_status:long} %{NUMBER:iis.access.win32\_status:long} %{NUMBER:temp.duration:long}",  
"%{TIMESTAMP\_ISO8601:iis.access.time} %{IPORHOST:destination.address} %{WORD:http.request.method} %{URIPATH:url.path} %{NOTSPACE:url.query} %{NUMBER:destination.port:long} %{NOTSPACE:user.name} %{IPORHOST:source.address} %{NOTSPACE:user\_agent.original} %{NUMBER:http.response.status\_code:long} %{NUMBER:iis.access.sub\_status:long} %{NUMBER:iis.access.win32\_status:long} %{NUMBER:temp.duration:long}"  
],  
"ignore\_missing": true  
}  
},  
{  
"remove": {  
"field": "message"  
}  
},  
{  
"rename": {  
"field": "@timestamp",  
"target\_field": "event.created"  
}  
},  
{  
"date": {  
"field": "iis.access.time",  
"target\_field": "@timestamp",  
"formats": [  
"yyyy-MM-dd HH:mm:ss"  
]  
}  
},  
{  
"remove": {  
"field": "iis.access.time"  
}  
},  
{  
"script": {  
"lang": "painless",  
"source": "ctx.event.duration = Math.round(ctx.temp.duration \* params.scale)",  
"params": {  
"scale": 1000000  
},  
"if": "ctx.temp?.duration != null"  
}  
},  
{  
"remove": {  
"field": "temp.duration",  
"ignore\_missing": true  
}  
},  
{  
"urldecode": {  
"field": "user\_agent.original"  
}  
},  
{  
"user\_agent": {  
"field": "user\_agent.original"  
}  
},  
{  
"grok": {  
"field": "destination.address",  
"ignore\_failure": true,  
"patterns": [  
"%{NOZONEIP:destination.ip}"  
],  
"pattern\_definitions": {  
"NOZONEIP": "[^%]_"  
}  
}  
},  
{  
"grok": {  
"field": "source.address",  
"ignore\_failure": true,  
"patterns": [  
"%{NOZONEIP:source.ip}"  
],  
"pattern\_definitions": {  
"NOZONEIP": "[^%]_"  
}  
}  
},  
{  
"geoip": {  
"field": "source.ip",  
"target\_field": "source.geo",  
"ignore\_missing": true  
}  
},  
{  
"geoip": {  
"database\_file": "GeoLite2-ASN.mmdb",  
"field": "source.ip",  
"target\_field": "source.as",  
"properties": [  
"asn",  
"organization\_name"  
],  
"ignore\_missing": true  
}  
},  
{  
"rename": {  
"field": "source.as.asn",  
"target\_field": "source.as.number",  
"ignore\_missing": true  
}  
},  
{  
"rename": {  
"field": "source.as.organization\_name",  
"target\_field": "source.as.organization.name",  
"ignore\_missing": true  
}  
}  
],  
"on\_failure": [  
{  
"set": {  
"field": "error.message",  
"value": "{{ \_ingest.on\_failure\_message }}"  
}  
}  
]  
}

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 27, 2019, 6:08am UTC](https://discuss.elastic.co/t/filebeat-to-match-iis-logs-timestamp/209565/2 "2019-11-27T06:08:03Z")

</div>

Is there a problem with this pipeline? If so, what is the problem? It would help if you provided additional information and context and asked a question.

---

<div class="post-metadata">

**Author:** ![alexserd](https://avatars.discourse-cdn.com/v4/letter/a/f17d59/32.png) [@alexserd](https://discuss.elastic.co/u/alexserd)\
**Post date:** [November 27, 2019, 6:27pm UTC](https://discuss.elastic.co/t/filebeat-to-match-iis-logs-timestamp/209565/3 "2019-11-27T18:27:21Z")

</div>

Christian, we are using ELK + Filebeat to ingest logs from IIS server. We had an issue where the service was not running and some old IIS logs were not imported from 2 weeks ago. I've turned filebeat service and the logs got ingested but the timestamp was used as current time of import. I would like logstash to read timestamp on the actual logs. I found these articles describing similar issue I tried to follow the steps described however was not successful.

> [@Filebeat Grok for Date IIS logs](https://discuss.elastic.co/t/filebeat-grok-for-date-iis-logs/147659/9):
>
> Ahhhh. Thank you! I just learnt something new, again slight_smile OK, I'll do it tomorrow morning first thing then I'll send you an update.

> [@Filebeat Grok for Date IIS logs](https://discuss.elastic.co/t/filebeat-grok-for-date-iis-logs/147659/10):
>
> Hi Noemi I ran the command you gave but got an error that --pipelines and --update-pipelines commands do not exist. However, running the below worked. D:\filebeat\>filebeat setup --modules=iis\_custom Loaded index template Loaded dashboards Loaded machine learning job configurations Unfortunately I am still getting the same error. I proceeded to make the log file even simpler by just leaving the date (without the time) to make it as simple as possible, but unfortunately, still the same err…

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 25, 2019, 8:27pm UTC](https://discuss.elastic.co/t/filebeat-to-match-iis-logs-timestamp/209565/4 "2019-12-25T20:27:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
