# Grok filter working, not extracting fields

**URL:** <https://discuss.elastic.co/t/grok-filter-working-not-extracting-fields/33965>\
**Category:** Logstash\
**Created:** [November 6, 2015, 9:23am UTC](https://discuss.elastic.co/t/grok-filter-working-not-extracting-fields/33965 "2015-11-06T09:23:41Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![laurentiu](https://avatars.discourse-cdn.com/v4/letter/l/ba8739/32.png) [@laurentiu](https://discuss.elastic.co/u/laurentiu)\
**Post date:** [November 6, 2015, 9:23am UTC](https://discuss.elastic.co/t/grok-filter-working-not-extracting-fields/33965/1 "2015-11-06T09:23:41Z")

</div>

Hi,  
I have an issue - I am trying to parse IIS logs but I am not getting any fields extracted. (I tested the filter against an log line in GROK Debugger and it seems fine).  
The logs look like this:  
2015-11-06 08:46:00 10.159.100.38 GET /portal2/api/internals/header culture= 80 - 54.72.165.221 - - 200 0 0 15  
2015-11-06 08:46:00 10.159.100.38 GET /idsrv/api/services/header culture= 80 - 54.72.165.221 - - 200 0 0 93  
The filter looks like this:  
filter {  
if [message] =~ "^#" {  
drop {}  
}  
if [type] == "iis" {  
grok {  
match =\> { "message" =\> "%{TIMESTAMP\_ISO8601:timestamp} %{IPORHOST:hostip} %{WORD:method} %{URIPATH:page} %{NOTSPACE:query} %{NUMBER:port} %{NOTSPACE:username} %{IPORHOST:clientip} %{NOTSPACE:useragent} %{NOTSPACE:referrer} %{NUMBER:response} %{NUMBER:subresponse} %{NUMBER:scstatus} %{NUMBER:timetaken}\r"}  
}  
}  
}

The output from the logstash.stdout is this:  
{  
"message" =\> "2015-11-06 09:14:13 10.159.100.38 GET /Portal2/Home/SearchByKeyData query=00370716486988244946 80 DSG 80.254.154.59 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.31+(KHTML,+like+Gecko)+Chrome/26.0.1410.64+Safari/537.31 [http://www.site.com/Portal2/Home](http://www.site.com/Portal2/Home) 200 0 0 4773\r",  
"@version" =\> "1",  
"@timestamp" =\> "2015-11-06T09:14:12.382Z",  
"host" =\> "10.159.100.38",  
"type" =\> "IIS"  
}

Am I doing something wrong? Why don't I see any fields extracted?

Also - Logstash is the latest version, 2.0.0 and I am using nxlog to send the logs.

(Log lines are different (in example and in stdout), the behavior is the same).

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 6, 2015, 9:28am UTC](https://discuss.elastic.co/t/grok-filter-working-not-extracting-fields/33965/2 "2015-11-06T09:28:04Z")

</div>

String comparisons are case-sensitive. Your `type` field contains "IIS" but the conditional in your configuration file checks for equality against "iis".

---

<div class="post-metadata">

**Author:** ![laurentiu](https://avatars.discourse-cdn.com/v4/letter/l/ba8739/32.png) [@laurentiu](https://discuss.elastic.co/u/laurentiu)\
**Post date:** [November 6, 2015, 9:29am UTC](https://discuss.elastic.co/t/grok-filter-working-not-extracting-fields/33965/3 "2015-11-06T09:29:47Z")

</div>

And it works like a charm.  
Thanks for the help (I feel stupid!)!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:23am UTC](https://discuss.elastic.co/t/grok-filter-working-not-extracting-fields/33965/4 "2017-07-06T05:23:40Z")

</div>


