Does filebeat support IIS logs per site (not server)?
For instance, filebeat is configured as such:
C:\inetpub\logs\LogFiles**.log
The LogFiles directory contains W3SVC1 and W3SVC2. Each subdirectory will have a log file with today's date, for instance: u_ex160621.log
From what the filebeat log file shows, the data appears to be valid:
W3SVC2:
2016-06-21T09:32:51-06:00 DBG Publish: {
"@timestamp": "2016-06-21T15:32:51.820Z",
"beat": {
"hostname": "SERVER1",
"name": "SERVER1"
},
"count": 1,
"fields": null,
"input_type": "log",
"message": "2016-06-21 00:08:55 W3SVC2 SERVER1 10.0.0.5 GET / - 443 - 10.0.0.1 - - 401 0 0 2293 7 2",
"offset": 10469,
"source": "C:\inetpub\logs\LogFiles\W3SVC2\u_ex160621.log",
"type": "log"
}
W3SVC4:
2016-06-21T09:32:51-06:00 DBG Publish: {
"@timestamp": "2016-06-21T15:32:51.823Z",
"beat": {
"hostname": "SERVER1",
"name": "SERVER1"
},
"count": 1,
"fields": null,
"input_type": "log",
"message": "2016-06-21 00:06:38 W3SVC4 SERVER1 10.0.0.5 GET / - 80 - 10.0.0.1 - - 404 0 64 2896 7 3",
"offset": 7809,
"source": "C:\inetpub\logs\LogFiles\W3SVC4\u_ex160621.log",
"type": "log"
}
However, all of my log timestamps in Kibana show a time of midnight, which is the first entry from the log file being read.