I'm not sure DATE_EN is even a valid pattern, but even if it is I suspect it's the wrong pattern to use for yyyy-mm-dd dates. I suggest you use TIMESTAMP_ISO8601 to match both the date and the time.
If things still don't work after making that change, start with the simplest possible expression,
^{TIMESTAMP_ISO8601:timestamp}
and make sure that works. Then add the next token,
^{TIMESTAMP_ISO8601:timestamp} %{IP:server_ip}
and the next, and so on until things break. Then you know what part of the expression is bad.
I'm not sure what's wrong here. If you start Logstash with --verbose or --debug it'll list exactly which pattern files and which patterns are loaded. Perhaps that'll give you some clues.
Thank you very much for your help
Use % {IISLOG} He has already started to work.
But I did not do what I don't know much about it This is the reason why.
Overall my problem has been solved.Thank you very much for your know.thank you
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.