# IIS module under filebeat not populating fields in discover

**URL:** <https://discuss.elastic.co/t/iis-module-under-filebeat-not-populating-fields-in-discover/321242>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [December 14, 2022, 9:21pm UTC](https://discuss.elastic.co/t/iis-module-under-filebeat-not-populating-fields-in-discover/321242 "2022-12-14T21:21:48Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Priya\_Vardhan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/priya_vardhan/32/99176_2.png) [@Priya\_Vardhan](https://discuss.elastic.co/u/Priya_Vardhan)\
**Post date:** [December 14, 2022, 9:21pm UTC](https://discuss.elastic.co/t/iis-module-under-filebeat-not-populating-fields-in-discover/321242/1 "2022-12-14T21:21:48Z")

</div>

Hi All,

I have enabled IIS module under filebeat after providing the log path for both access and error.

I can see the IIS fields getting loaded in filebeat index, but it is not showing in discover.

The data is not available for IIS.

Any help would be appreciated?

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [December 14, 2022, 10:01pm UTC](https://discuss.elastic.co/t/iis-module-under-filebeat-not-populating-fields-in-discover/321242/2 "2022-12-14T22:01:48Z")

</div>

It sounds like you are having trouble viewing your IIS logs in the Discover page of the Elastic Stack. There are a few potential reasons for this:

- The Filebeat index pattern may not be set up correctly in Elasticsearch. In order for the data to be searchable in Discover, you will need to create an index pattern that matches the name of the index that Filebeat is writing to. You can do this by going to the Management tab in Kibana, then selecting Index Patterns and creating a new pattern.
- If the index pattern is set up correctly, the issue may be with the configuration of Filebeat. Make sure that the `fields` section of the Filebeat configuration file includes the IIS fields that you want to be available in Discover. Additionally, check that the `fields_under_root` and `fields.yml` files are set up correctly, as these can affect how fields are indexed in Elasticsearch.
- It is also possible that there is a problem with the data being ingested by Filebeat. If the IIS logs are not being parsed correctly, the relevant fields may not be available in Elasticsearch. You can check the Filebeat logs to see if there are any error messages that can help identify the cause of the issue.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [December 14, 2022, 10:08pm UTC](https://discuss.elastic.co/t/iis-module-under-filebeat-not-populating-fields-in-discover/321242/3 "2022-12-14T22:08:21Z")

</div>

Or need to expand the time picker 🙂

Hi @Priya_Vardhan Welcome to the community!

---

<div class="post-metadata">

**Author:** ![Priya\_Vardhan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/priya_vardhan/32/99176_2.png) [@Priya\_Vardhan](https://discuss.elastic.co/u/Priya_Vardhan)\
**Post date:** [December 14, 2022, 10:33pm UTC](https://discuss.elastic.co/t/iis-module-under-filebeat-not-populating-fields-in-discover/321242/4 "2022-12-14T22:33:46Z")

</div>

Hi @aaron-nimocks and @stephenb ,

Thanks for the info.

1. Index pattern is setup correctly, as it is loading the data for other fields other than IIS
2. Fields.yml looks fine
3. Filebeat logs are producing some errors like below

Type : mapper parsing exception, reason : failed to parse field [network forwarded ip] of type [ip] in document with I'd "".  
Reason: 350 is not an ip string literal

There is another error in kibana like " Provided Grok expressions do not match field value"

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [December 14, 2022, 10:41pm UTC](https://discuss.elastic.co/t/iis-module-under-filebeat-not-populating-fields-in-discover/321242/5 "2022-12-14T22:41:11Z")

</div>

What was the value of the field in the error? If it's not a valid IP address then that's what would cause this issue.

---

<div class="post-metadata">

**Author:** ![Priya\_Vardhan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/priya_vardhan/32/99176_2.png) [@Priya\_Vardhan](https://discuss.elastic.co/u/Priya_Vardhan)\
**Post date:** [December 14, 2022, 10:49pm UTC](https://discuss.elastic.co/t/iis-module-under-filebeat-not-populating-fields-in-discover/321242/6 "2022-12-14T22:49:32Z")

</div>

@aaron-nimocks - It is as below  
Provided Grok expressions do not match field value: [2021-08-12 19:09:09 10.xx.xxx.xx 34169 10.xx.xxx.xxx 81 - %00 %00 400 - Bad request -]

How to fix this issue if it is due to IP?

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [December 14, 2022, 10:59pm UTC](https://discuss.elastic.co/t/iis-module-under-filebeat-not-populating-fields-in-discover/321242/7 "2022-12-14T22:59:49Z")

</div>

Ohh. Looks like you have a grok or dissect issue somewhere. Did you run the [setup from filebeats](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-installation-configuration.html#setup-assets) that pushed templates and such to Kibana? Specifically I am wondering if the ingest pipelines are loaded.

---

<div class="post-metadata">

**Author:** ![Priya\_Vardhan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/priya_vardhan/32/99176_2.png) [@Priya\_Vardhan](https://discuss.elastic.co/u/Priya_Vardhan)\
**Post date:** [December 14, 2022, 11:22pm UTC](https://discuss.elastic.co/t/iis-module-under-filebeat-not-populating-fields-in-discover/321242/8 "2022-12-14T23:22:40Z")

</div>

yes, I ran the setup and ingest pipelines are loaded in Kibana.  
Do we need to configure ingest pipeline in filebeat config files?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 12, 2023, 1:23am UTC](https://discuss.elastic.co/t/iis-module-under-filebeat-not-populating-fields-in-discover/321242/9 "2023-01-12T01:23:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
