# Grok Filter not extracting the fields

**URL:** <https://discuss.elastic.co/t/grok-filter-not-extracting-the-fields/92822>\
**Category:** Logstash\
**Created:** [July 12, 2017, 2:27pm UTC](https://discuss.elastic.co/t/grok-filter-not-extracting-the-fields/92822 "2017-07-12T14:27:07Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![birdman](https://avatars.discourse-cdn.com/v4/letter/b/90ced4/32.png) [@birdman](https://discuss.elastic.co/u/birdman)\
**Post date:** [July 12, 2017, 2:27pm UTC](https://discuss.elastic.co/t/grok-filter-not-extracting-the-fields/92822/1 "2017-07-12T14:27:08Z")

</div>

Hey, My grok filter is working but not extracting and here is the logstash.conf

```
    input { 
      beats {
        port => 5044
      }
    }
    filter {
      if [type] == "iis" {
    		if [message] =~ "^#" {
                    drop {}
            }
    	   grok {
    			match => { "message" => "%{TIMESTAMP_ISO8601:log_timestamp} %{WORD:S-SiteName} %{NOTSPACE:S-ComputerName} %{IPORHOST:S-IP} %{WORD:CS-Method} %{URIPATH:CS-URI-Stem} (?:-|\"%{URIPATH:CS-URI-Query}\") %{NUMBER:Port} %{NOTSPACE:CS-Username} %{IPORHOST:C-IP} %{NOTSPACE:CS-Version} %{NOTSPACE:CS-UserAgent} %{NOTSPACE:CS-Cookie} %{NOTSPACE:CS-Referer} %{NOTSPACE:CS-Host} %{NUMBER:SC-Status} %{NUMBER:SC-SubStatus} %{NUMBER:SC-Win32-Status} %{NUMBER:SC-Bytes} %{NUMBER:CS-Bytes} %{NUMBER:Time-Taken}"}
    		}
        }
    }	
    output {
       elasticsearch {
        hosts => ["locahost:5555"]
        manage_template => false
        index => "%{[@metadata][beat]}-%{+YYYY.MM.dd}"
        document_type => "%{[@metadata][type]}"
      }
    }

```

and here is filebeat.config

```
filebeat.prospectors:
    - input_type: log
      paths:
        - c:\inetpub\logs\LogFiles\W3SVC1\*.log
      document_type: iis

    output.logstash:
      hosts: ["localhost"]

```

and kibana output:

@timestamp  
July 12th 2017, 09:13:50.545  
t @version  
1  
t \_id

t \_index   
filebeat-2017.07.12

# \_score

```
 - 

```

t \_type   
log  
t beat.hostname   
symwork  
t [beat.name](http://beat.name)  
symwork  
t beat.version   
5.4.0  
t host   
symwork  
t input\_type   
log  
t message   
2017-07-12 14:12:59 W3SVC1 symworkflow ip POST /Green/WorkflowManagementService.asmx - 900- clientip HTTP/1.0 Mozilla/4.0+(compatible;+MSIE+6.0;+MS+Web+Services+Client+Protocol+) - - [b.p.com](http://b.p.com) 500 1 1 900 700 9

# offset

```
1,229,523

```

t source   
c:\inetpub\logs\LogFiles\W3SVC1\u\_ex170712.log  
t tags   
beats\_input\_codec\_plain\_applied  
t type   
log

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 12, 2017, 2:34pm UTC](https://discuss.elastic.co/t/grok-filter-not-extracting-the-fields/92822/2 "2017-07-12T14:34:12Z")

</div>

The `type` field contains "log" but you're only applying the grok filter to "iis" events.

If you format your Filebeat configuration as preformatted text it won't be damaged when you post it and we can probably point out what's wrong.

---

<div class="post-metadata">

**Author:** ![birdman](https://avatars.discourse-cdn.com/v4/letter/b/90ced4/32.png) [@birdman](https://discuss.elastic.co/u/birdman)\
**Post date:** [July 12, 2017, 2:37pm UTC](https://discuss.elastic.co/t/grok-filter-not-extracting-the-fields/92822/3 "2017-07-12T14:37:36Z")

</div>

Thanks for reply. I'm new to logstash and elastic. I just preformatted the text for filebeat

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 12, 2017, 2:56pm UTC](https://discuss.elastic.co/t/grok-filter-not-extracting-the-fields/92822/4 "2017-07-12T14:56:17Z")

</div>

Hmm, looks correct. I'm not sure what's up here.

---

<div class="post-metadata">

**Author:** ![birdman](https://avatars.discourse-cdn.com/v4/letter/b/90ced4/32.png) [@birdman](https://discuss.elastic.co/u/birdman)\
**Post date:** [July 12, 2017, 2:59pm UTC](https://discuss.elastic.co/t/grok-filter-not-extracting-the-fields/92822/5 "2017-07-12T14:59:06Z")

</div>

Thats What I thought. I restarted the logstash container and filebeat in windowsserver and kibana. I'm not sure why is not extracting the field

---

<div class="post-metadata">

**Author:** ![birdman](https://avatars.discourse-cdn.com/v4/letter/b/90ced4/32.png) [@birdman](https://discuss.elastic.co/u/birdman)\
**Post date:** [July 13, 2017, 12:54pm UTC](https://discuss.elastic.co/t/grok-filter-not-extracting-the-fields/92822/6 "2017-07-13T12:54:56Z")

</div>

Figure It out. I was missing - type =\> iis in the logstash input field

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 13, 2017, 2:16pm UTC](https://discuss.elastic.co/t/grok-filter-not-extracting-the-fields/92822/7 "2017-07-13T14:16:06Z")

</div>

That works too, but makes it harder to collect different kinds of logs with the same beats input.

---

<div class="post-metadata">

**Author:** ![birdman](https://avatars.discourse-cdn.com/v4/letter/b/90ced4/32.png) [@birdman](https://discuss.elastic.co/u/birdman)\
**Post date:** [July 13, 2017, 8:10pm UTC](https://discuss.elastic.co/t/grok-filter-not-extracting-the-fields/92822/8 "2017-07-13T20:10:09Z")

</div>

That makes sense. If I don't put in the input type, It wont work.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 10, 2017, 8:10pm UTC](https://discuss.elastic.co/t/grok-filter-not-extracting-the-fields/92822/9 "2017-08-10T20:10:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
