It looks to me like there is nothing matching the iisSite field as the timestamp is directly followed by an IP. The ending of the expression also seems off.
Thank you for your quick reply. I deleted the iisSite field from my config and it still doesn't work
This is one of my mst recent messages 2018-12-18 11:41:31 192.168.1.8 HEAD 1812185441 8530 - 192.168.3.15 Windows-Update-Agent - 200 0 0 273 209
I would recommend building the pattern step-by-step as described in this blog post. That is generally the recommended way to create and/or debug grok expressions.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.