# How to put two groks for IIS Logs?

**URL:** <https://discuss.elastic.co/t/how-to-put-two-groks-for-iis-logs/256111>\
**Category:** Logstash\
**Created:** [November 20, 2020, 11:52am UTC](https://discuss.elastic.co/t/how-to-put-two-groks-for-iis-logs/256111 "2020-11-20T11:52:47Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Cristiane\_Marcarini](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cristiane_marcarini/32/79393_2.png) [@Cristiane\_Marcarini](https://discuss.elastic.co/u/Cristiane_Marcarini)\
**Post date:** [November 20, 2020, 11:52am UTC](https://discuss.elastic.co/t/how-to-put-two-groks-for-iis-logs/256111/1 "2020-11-20T11:52:47Z")

</div>

\<grok  
{  
break\_on\_match =\> true  
match =\> ["message", "%{TIMESTAMP\_ISO8601:log\_timestamp} %{IPORHOST:site} %{WORD:method} %{URIPATH:request}(?:%{URIPARAM:requestparam})? - %{NUMBER:port} - %{IPORHOST:clienthost} %{NOTSPACE:useragent} %{NUMBER:response} %{NUMBER:subresponse} %{NUMBER:win32response} %{NUMBER:bytesSent} %{NUMBER:bytesReceived} %{NUMBER:timetaken}"]  
match =\> ["message", "%{TIMESTAMP\_ISO8601:log\_timestamp} %{IPORHOST:site} %{WORD:method} %{URIPATH:cs\_uri\_stem} - %{NUMBER:port} %{NOTSPACE:username} %{IPORHOST:clienthost} %{NOTSPACE:useragent} %{NUMBER:response} %{NUMBER:subresponse} %{NUMBER:win32response} %{NUMBER:bytesSent} %{NUMBER:bytesReceived} %{NUMBER:timetaken}"]

```
	}>
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 20, 2020, 2:18pm UTC](https://discuss.elastic.co/t/how-to-put-two-groks-for-iis-logs/256111/2 "2020-11-20T14:18:55Z")

</div>

If you want to match against two patterns then use

```
grok {
    match => {
        "message" => [
            "%{TIMESTAMP_ISO8601:log_timestamp} %{IPORHOST:site} %{WORD:method} %{URIPATH:request}(?:%{URIPARAM:requestparam})? - %{NUMBER:port} - %{IPORHOST:clienthost} %{NOTSPACE:useragent} %{NUMBER:response} %{NUMBER:subresponse} %{NUMBER:win32response} %{NUMBER:bytesSent} %{NUMBER:bytesReceived} %{NUMBER:timetaken}",
            "%{TIMESTAMP_ISO8601:log_timestamp} %{IPORHOST:site} %{WORD:method} %{URIPATH:cs_uri_stem} - %{NUMBER:port} %{NOTSPACE:username} %{IPORHOST:clienthost} %{NOTSPACE:useragent} %{NUMBER:response} %{NUMBER:subresponse} %{NUMBER:win32response} %{NUMBER:bytesSent} %{NUMBER:bytesReceived} %{NUMBER:timetaken}"
        ]
    }
}
```

---

<div class="post-metadata">

**Author:** ![Cristiane\_Marcarini](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cristiane_marcarini/32/79393_2.png) [@Cristiane\_Marcarini](https://discuss.elastic.co/u/Cristiane_Marcarini)\
**Post date:** [November 23, 2020, 2:24pm UTC](https://discuss.elastic.co/t/how-to-put-two-groks-for-iis-logs/256111/3 "2020-11-23T14:24:47Z")

</div>

**This is my Logstash file, am I doing it wrong?**

\<input  
{  
file  
{  
path =\> [  
"C:/Elastic\_stack/logs/IISLogs/_u\_ex_.log"  
]   
start\_position =\> "beginning"  
sincedb\_path =\> "NUL"

```
}

```

}  
filter  
{  
if "logs" in [path]  
{

```
	grok {
		match => {
			"message" => [
							"%{TIMESTAMP_ISO8601:log_timestamp} %{IPORHOST:site} %{WORD:method} %{URIPATH:request}(?:%{URIPARAM:requestparam})? - %{NUMBER:port} - %{IPORHOST:clienthost} %{NOTSPACE:useragent} %{NUMBER:response} %{NUMBER:subresponse} %{NUMBER:win32response} %{NUMBER:bytesSent} %{NUMBER:bytesReceived} %{NUMBER:timetaken}",
							"%{TIMESTAMP_ISO8601:log_timestamp} %{IPORHOST:site} %{WORD:method} %{URIPATH:cs_uri_stem} - %{NUMBER:port} %{NOTSPACE:username} %{IPORHOST:clienthost} %{NOTSPACE:useragent} %{NUMBER:response} %{NUMBER:subresponse} %{NUMBER:win32response} %{NUMBER:bytesSent} %{NUMBER:bytesReceived} %{NUMBER:timetaken}"
						]
		}
	}
	

	# set the event timestamp from the log
	date 
	{
		match => ["log_timestamp", "YYYY-MM-dd HH:mm:ss"]
		timezone => "Etc/UCT"
	}

	# matches the big, long nasty useragent string to the actual browser name, version, etc
	mutate 
	{
		remove_field => ["log_timestamp"]
	}
}
fingerprint 
{
	id => "ApplicationLogs"
	source => ["@timestamp","message"]
	target => "[fingerprint]"
	key => "78787878"
	method => "SHA1"
	concatenate_sources => true
}

```

}  
output  
{  
stdout  
{  
codec =\> rubydebug  
}  
if "IISLogs" in [path]  
{  
elasticsearch  
{  
hosts =\> ["[http://localhost:9200](http://localhost:9200)"]  
document\_id =\> "%{[fingerprint]}"  
index =\> "u\_ex\_pl\_sim-%{+YYYY.MM.dd}"  
}  
}   
}\>

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 23, 2020, 2:47pm UTC](https://discuss.elastic.co/t/how-to-put-two-groks-for-iis-logs/256111/4 "2020-11-23T14:47:47Z")

</div>

That looks reasonable, what do you not like about the output?

BTW, when posting configurations please select the configuration and use the \</\> button in the toolbar above the edit pane. That will preserve the formatting of the configuration. Notice how in your last post the formatting of the grok and date filters are preserved, but the formatting of the input section is not. If you use \</\> the formatting is preserved everywhere, which makes the configuration much easier to read.

---

<div class="post-metadata">

**Author:** ![Cristiane\_Marcarini](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cristiane_marcarini/32/79393_2.png) [@Cristiane\_Marcarini](https://discuss.elastic.co/u/Cristiane_Marcarini)\
**Post date:** [November 23, 2020, 4:38pm UTC](https://discuss.elastic.co/t/how-to-put-two-groks-for-iis-logs/256111/5 "2020-11-23T16:38:05Z")

</div>

\<

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/7/87c333ca41217eb69e3d7a5bccf471776260a4ec.png) \>

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 21, 2020, 4:38pm UTC](https://discuss.elastic.co/t/how-to-put-two-groks-for-iis-logs/256111/6 "2020-12-21T16:38:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
