# Filter does not seem to supply logs for kibana

**URL:** <https://discuss.elastic.co/t/filter-does-not-seem-to-supply-logs-for-kibana/121932>\
**Category:** Logstash\
**Created:** [February 28, 2018, 8:00pm UTC](https://discuss.elastic.co/t/filter-does-not-seem-to-supply-logs-for-kibana/121932 "2018-02-28T20:00:11Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![irb7501](https://avatars.discourse-cdn.com/v4/letter/i/d9b06d/32.png) [@irb7501](https://discuss.elastic.co/u/irb7501)\
**Post date:** [February 28, 2018, 8:00pm UTC](https://discuss.elastic.co/t/filter-does-not-seem-to-supply-logs-for-kibana/121932/1 "2018-02-28T20:00:12Z")

</div>

I have an IIS filter that seems to test fine using the grok debugger however I am not seeing any messages indexed in Kibana via filebeat. Here is my beats.conf

input{  
beats{  
port =\> "5043"  
}  
}

filter {  
if [type] == "syslog" {  
grok {  
match =\> { "message" =\> "%{SYSLOGTIMESTAMP:syslog\_timestamp} %{SYSLOGHOST:syslog\_hostname} %{DATA:syslog\_program}(?:[%{POSINT:syslog\_pid}])?: %{GREEDYDATA:syslog\_message}" }  
}  
date {  
match =\> ["syslog\_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]  
}  
}

```
if [type] == "iis_log" {
    if [message] =~ "^#" {
        drop {}
    }

    grok {
        match => { "message" => ["%{TIMESTAMP_ISO8601:log_timestamp} %{WORD:iisSite} %{IPORHOST:site} %{WORD:method} %{URIPATH:page} %{NOTSPACE:querystring} %{NUMBER:port} %{NOTSPACE:username} %{IPORHOST:clienthost} %{NOTSPACE:useragent} %{NOTSPACE:referer}"] }
    }

}

```

}

output{  
elasticsearch {  
hosts =\> ["192.168.1.1:9200"]  
index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
document\_type =\> "%{[@metadata][type]}"  
}  
}

Here is an excerpt from the IIS log:

#Fields: date time s-computername s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) cs-host sc-status sc-substatus sc-win32-status sc-bytes cs-bytes time-taken  
2018-02-28 08:33:38 host123 192.168.1.100 GET /some/internal/directory - 443 [user@emailaddress.com](mailto:user@emailaddress.com) 192.168.1.101 product/version+build;+iOS+version)+product/1.0 - [site.external.com](http://site.external.com) 123 0 0 233 123 4321

The grok debugger tells me that some of my fields are matching what IIS logs are supplying.

Here is the filebeat.yml

filebeat.prospectors:

- type: log

filebeat.config.modules:  
path: ${path.config}/modules.d/\*.yml

reload.enabled: false

setup.template.settings:  
index.number\_of\_shards: 3

tags: ["location", "web Farm"]

fields:  
environment: production

setup.kibana:

host: "192.168.1.1:5601"

output.logstash:  
hosts: ["192.168.1.1:5043"]

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 28, 2018, 8:36pm UTC](https://discuss.elastic.co/t/filter-does-not-seem-to-supply-logs-for-kibana/121932/2 "2018-02-28T20:36:46Z")

</div>

Have you checked the Logstash logs for problems? Have you checked if the data is added to a different index than what you expect (use ES's cat indices API)?

---

<div class="post-metadata">

**Author:** ![pjanzen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pjanzen/32/13756_2.png) [@pjanzen](https://discuss.elastic.co/u/pjanzen)\
**Post date:** [March 1, 2018, 8:28am UTC](https://discuss.elastic.co/t/filter-does-not-seem-to-supply-logs-for-kibana/121932/3 "2018-03-01T08:28:09Z")

</div>

Are you sure the type is iis\_log? you could add a rubydebug to your output and check. you can also set document\_type: in you iis\_log prospector, that might help your problem.

---

<div class="post-metadata">

**Author:** ![irb7501](https://avatars.discourse-cdn.com/v4/letter/i/d9b06d/32.png) [@irb7501](https://discuss.elastic.co/u/irb7501)\
**Post date:** [March 1, 2018, 1:31pm UTC](https://discuss.elastic.co/t/filter-does-not-seem-to-supply-logs-for-kibana/121932/4 "2018-03-01T13:31:54Z")

</div>

When I restart logstash I see the following warnings:

[2018-03-01T08:26:49,961][WARN][logstash.outputs.elasticsearch] You are using a deprecated config setting "document\_type" set in elasticsearch. Deprecated settings will continue to work, but are scheduled for removal from logstash in the future. Document types are being deprecated in Elasticsearch 6.0, and removed entirely in 7.0. You should avoid this feature If you have any questions about this, please visit the #logstash channel on freenode irc. {:name=\>"document\_type", :plugin=\>\<LogStash::Outputs::ElasticSearch hosts=\>[[//192.168.1.1:9200](https://192.168.1.1:9200)], index=\>"%{[@metadata][beat]}-%{+YYYY.MM.dd}", document\_type=\>"%{[@metadata][type]}", id=\>"97fff7e442252ff4e458bd02f090f79a6de076c520ff83a8a0ce90b047e97b00", enable\_metric=\>true, codec=\>\<LogStash::Codecs::Plain id=\>"plain\_6d1711a2-34a5-4d91-bfe9-8422f64f84f9", enable\_metric=\>true, charset=\>"UTF-8"\>, workers=\>1, manage\_template=\>true, template\_name=\>"logstash", template\_overwrite=\>false, doc\_as\_upsert=\>false, script\_type=\>"inline", script\_lang=\>"painless", script\_var\_name=\>"event", scripted\_upsert=\>false, retry\_initial\_interval=\>2, retry\_max\_interval=\>64, retry\_on\_conflict=\>1, action=\>"index", ssl\_certificate\_verification=\>true, sniffing=\>false, sniffing\_delay=\>5, timeout=\>60, pool\_max=\>1000, pool\_max\_per\_route=\>100, resurrect\_delay=\>5, validate\_after\_inactivity=\>10000, http\_compression=\>false\>}

[2018-03-01T08:26:50,497][WARN][logstash.outputs.elasticsearch] Detected a 6.x and above cluster: the `type` event field won't be used to determine the document \_type {:es\_version=\>6}

in my filebeat.yml I have "document\_type: iis\_log"

I have refreshed the field list for all my indices.

---

<div class="post-metadata">

**Author:** ![irb7501](https://avatars.discourse-cdn.com/v4/letter/i/d9b06d/32.png) [@irb7501](https://discuss.elastic.co/u/irb7501)\
**Post date:** [March 1, 2018, 1:40pm UTC](https://discuss.elastic.co/t/filter-does-not-seem-to-supply-logs-for-kibana/121932/5 "2018-03-01T13:40:04Z")

</div>

OK I feel silly. I suppose if I set enabled to true it might just work...

filebeat.prospectors:

•type: log

enabled: false

(2 min later...) what do you know it works. thanks for the help!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 29, 2018, 1:40pm UTC](https://discuss.elastic.co/t/filter-does-not-seem-to-supply-logs-for-kibana/121932/6 "2018-03-29T13:40:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
