# Filebeat with IIS logs

**URL:** <https://discuss.elastic.co/t/filebeat-with-iis-logs/211756>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [December 13, 2019, 8:02am UTC](https://discuss.elastic.co/t/filebeat-with-iis-logs/211756 "2019-12-13T08:02:49Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Aleix\_Abrie\_Prat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aleix_abrie_prat/32/47196_2.png) [@Aleix\_Abrie\_Prat](https://discuss.elastic.co/u/Aleix_Abrie_Prat)\
**Post date:** [December 13, 2019, 8:02am UTC](https://discuss.elastic.co/t/filebeat-with-iis-logs/211756/1 "2019-12-13T08:02:49Z")

</div>

Hi everyone,

I have a doubt with the module for IIS logs. I configured the output of filebeat to connect directly with the elasticsearch and then I've have done the command ".\filebeat.exe setup to make the index in elasticsearch and the dashboards in kibana. But i have a problem...

With the index created automatically, the index doesn't have a field for the IP that comes from "X Forwarded for". Now, my question is:

Can i update the pipeline that parses the IIS logs to add the field for this IP?

Thanks for advance 🙂

---

<div class="post-metadata">

**Author:** ![ChrsMark](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrsmark/32/55858_2.png) [@ChrsMark](https://discuss.elastic.co/u/ChrsMark)\
**Post date:** [December 13, 2019, 9:50am UTC](https://discuss.elastic.co/t/filebeat-with-iis-logs/211756/2 "2019-12-13T09:50:41Z")

</div>

Hi!

You can find the fields that are exported [here](https://www.elastic.co/guide/en/beats/filebeat/master/exported-fields-iis.html).

If the filed you are looking for is not listed you can use an extra processor like `[https://www.elastic.co/guide/en/beats/filebeat/master/processor-script.html](https://www.elastic.co/guide/en/beats/filebeat/master/processor-script.html)script-processor` to further analyse the events.

If you think this field is important enough you can open a Github issue requesting for it (or if you want you can contribute it directly 🙂 ).

Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 10, 2020, 9:50am UTC](https://discuss.elastic.co/t/filebeat-with-iis-logs/211756/3 "2020-01-10T09:50:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
