# Filter IIS Log information

**URL:** <https://discuss.elastic.co/t/filter-iis-log-information/46209>\
**Category:** Logstash\
**Created:** [April 4, 2016, 7:38am UTC](https://discuss.elastic.co/t/filter-iis-log-information/46209 "2016-04-04T07:38:47Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![freichert](https://avatars.discourse-cdn.com/v4/letter/f/5f9b8f/32.png) [@freichert](https://discuss.elastic.co/u/freichert)\
**Post date:** [April 4, 2016, 7:38am UTC](https://discuss.elastic.co/t/filter-iis-log-information/46209/1 "2016-04-04T07:38:47Z")

</div>

Hello everybody,

i just set up the ELK Stack on an Ubuntu machine. Currently Logstash is processing the IIS Logs with a Grok Filter and Splits the information like it should. Now i am Stuck - i would like to "filter" the logs which are sent to the Logstash Server. Currently there are a lot of /health checks in the IIS log which i really dont need in Logstash. Is it possible to not send these lines of the Log? How could i Check for the "page" Part in the IIS log if it contains /health?

Result should be: send everything except the Loglines which are for the page /health

I couldnt find any fitting solutions around here.

Best regards and thanks in advance!

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 4, 2016, 7:39am UTC](https://discuss.elastic.co/t/filter-iis-log-information/46209/2 "2016-04-04T07:39:34Z")

</div>

How are you sending the IIS logs to Logstash?

---

<div class="post-metadata">

**Author:** ![freichert](https://avatars.discourse-cdn.com/v4/letter/f/5f9b8f/32.png) [@freichert](https://discuss.elastic.co/u/freichert)\
**Post date:** [April 4, 2016, 7:40am UTC](https://discuss.elastic.co/t/filter-iis-log-information/46209/3 "2016-04-04T07:40:13Z")

</div>

the Logs are sent via Filebeat. Sorry for the missing information. if you need any further just let me know.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 4, 2016, 7:41am UTC](https://discuss.elastic.co/t/filter-iis-log-information/46209/4 "2016-04-04T07:41:38Z")

</div>

The latest filebeat can exclude events - [https://www.elastic.co/guide/en/beats/filebeat/current/configuration-filebeat-options.html#exclude-lines](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-filebeat-options.html#exclude-lines)

---

<div class="post-metadata">

**Author:** ![freichert](https://avatars.discourse-cdn.com/v4/letter/f/5f9b8f/32.png) [@freichert](https://discuss.elastic.co/u/freichert)\
**Post date:** [April 4, 2016, 9:00am UTC](https://discuss.elastic.co/t/filter-iis-log-information/46209/5 "2016-04-04T09:00:01Z")

</div>

Hi warkolm,

thank you for the information! I have tried some things and came to the conclusion that i would like to handle it serverside. so i have got the configuration for that in one place. I have found a way via "drop" in the filter to drop the loglines. I just cant get it running. Could you have a look at the filter config what is wrong there?

> filter {  
> if [input\_type] == "iis" {  
> grok {  
> match =\> { "message" =\> "%{TIMESTAMP\_ISO8601:log\_timestamp} %{WORD:iisSite} %{IPORHOST:computername} %{IP:sourceip} %{WORD:csmethod} %{URIPATH:page} %{NOTSPACE:querystring} %{NUMBER:port} %{NOTSPACE:csusername} %{IP:cip} %{NOTSPACE:useragent} %{NOTSPACE:referer} %{NOTSPACE:cshost} %{NUMBER:scstatus} %{NUMBER:scsubstatus} %{NUMBER:scwin32status} %{NUMBER:scbytes} %{NUMBER:csbytes} %{NUMBER:timetaken}" }  
> }  
> if ([message] =~ "/health/") {  
> drop {}  
> }  
> }  
> }

when i run the configtest i get following error which i dont know how to handle:

> root@stw-ch-log-01:/etc/logstash/conf.d# service logstash configtest  
> SyntaxError: (eval):162: halth  
> unknown regexp options - halth  
> eval at org/jruby/RubyKernel.java:1079  
> initialize at /opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.2.2-java/lib/logstash/pipeline.rb:57  
> execute at /opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.2.2-java/lib/logstash/agent.rb:172  
> run at /opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.2.2-java/lib/logstash/runner.rb:90  
> call at org/jruby/RubyProc.java:281  
> run at /opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.2.2-java/lib/logstash/runner.rb:95  
> call at org/jruby/RubyProc.java:281  
> initialize at /opt/logstash/vendor/bundle/jruby/1.9/gems/stud-0.0.22/lib/stud/task.rb:24

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:04am UTC](https://discuss.elastic.co/t/filter-iis-log-information/46209/6 "2017-07-06T05:04:07Z")

</div>


