# Logstash-2.2.2, windows, IIS log file format

**URL:** <https://discuss.elastic.co/t/logstash-2-2-2-windows-iis-log-file-format/45501>\
**Category:** Logstash\
**Created:** [March 26, 2016, 6:19am UTC](https://discuss.elastic.co/t/logstash-2-2-2-windows-iis-log-file-format/45501 "2016-03-26T06:19:35Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![jack8653](https://avatars.discourse-cdn.com/v4/letter/j/9de0a6/32.png) [@jack8653](https://discuss.elastic.co/u/jack8653)\
**Post date:** [March 26, 2016, 6:19am UTC](https://discuss.elastic.co/t/logstash-2-2-2-windows-iis-log-file-format/45501/1 "2016-03-26T06:19:35Z")

</div>

Hello,

when I'm parsing iis log file in UTF-8 format I'm getting [0] "\_grokparsefailure" error and When I'm parsing log file using ANSI format there is nothing working Logstash just display message on console " Logstash startup completed". There is almost 1000 files on my server i can't change each file format from ANSI to UTF-8.  
Can you please help where I need to change in my config file. I'm also attaching debug file when I'm parsing files on UTF-8 format.  
I'm using elastic search on same box and its completely working fine. I'm also able to telnet port 9200 with 127.0.0.1.

2016-03-26T05:40:40.764Z WIN-AK44913P759 2016-03-24 00:16:31 W3SVC20 SANDBOXWEB01 172.x.x.x GET /healthmonitor.axd - 80 - 172.x.x.x HTTP/1.1 - - - [www.xyz.net](http://www.xyz.net) 200 0 0 4698 122 531  
{  
"message" =\> "2016-03-24 04:43:02 W3SVC20 ODSANDBOXWEB01 172.x.x.x GET /healthmonitor.axd - 80 - 172.x.x.x HTTP/1.1 - - - [www.xyz.net](http://www.xyz.net) 200 0 0 4698 122 703\r",  
"@version" =\> "1",  
"@timestamp" =\> "2016-03-26T05:42:15.045Z",  
"path" =\> "C:\IISLogs/u\_ex160324.log",  
"host" =\> "WIN-AK44913P759",  
"type" =\> "IISLog",  
"tags" =\> [  
[0] "\_grokparsefailure"  
]  
}

Below is my logstash conf file configuration  
input {  
file {  
type =\> "IISLog"  
path =\> "C:\IISLogs/u\_ex\*.log"  
start\_position =\> "beginning"  
}  
}  
filter {  
#ignore log comments  
if [message] =~ "^#" {  
drop {}  
}  
grok {  
match =\> ["message", "%{TIMESTAMP\_ISO8601:log\_timestamp} %{WORD:iisSite} %{IPORHOST:site} %{WORD:method} %{URIPATH:page} %{NOTSPACE:querystring} %{NUMBER:port} %{NOTSPACE:username} %{IPORHOST:clienthost} %{NOTSPACE:useragent} %{NOTSPACE:referer} %{NUMBER:response} %{NUMBER:subresponse} %{NUMBER:scstatus} %{NUMBER:bytes:int} %{NUMBER:timetaken:int}"]  
}  
#Set the Event Timesteamp from the log  
date {  
match =\> ["log\_timestamp", "YYYY-MM-dd HH:mm:ss"]  
timezone =\> "Etc/UCT"  
}   
useragent {  
source=\> "useragent"  
prefix=\> "browser"  
}  
mutate {  
remove\_field =\> ["log\_timestamp"]  
}  
}

# output logs to console and to elasticsearch

output {  
stdout {}  
elasticsearch {  
hosts =\> ["127.0.0.1:9200"]  
}  
stdout { codec =\> rubydebug }  
}

---

<div class="post-metadata">

**Author:** ![jack8653](https://avatars.discourse-cdn.com/v4/letter/j/9de0a6/32.png) [@jack8653](https://discuss.elastic.co/u/jack8653)\
**Post date:** [March 26, 2016, 1:54pm UTC](https://discuss.elastic.co/t/logstash-2-2-2-windows-iis-log-file-format/45501/2 "2016-03-26T13:54:05Z")

</div>

Hi Team,

Any update. This is bit urgent.

Thanks  
J

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 26, 2016, 2:42pm UTC](https://discuss.elastic.co/t/logstash-2-2-2-windows-iis-log-file-format/45501/3 "2016-03-26T14:42:55Z")

</div>

> [@jack8653](#):
>
> "message" =\> "2016-03-24 04:43:02 W3SVC20 ODSANDBOXWEB01 172.x.x.x GET /healthmonitor.axd - 80 - 172.x.x.x HTTP/1.1 - - - [www.xyz.net](http://www.xyz.net) 200 0 0 4698 122 703\r"

If you look at the message and line the components up against the parts of the grok expression they currently match, it is clear that several components have been overlooked and need to be added.

```
2016-03-24 04:43:02 -> %{TIMESTAMP_ISO8601:log_timestamp}
W3SVC20 -> %{WORD:iisSite}
ODSANDBOXWEB01 -> %{IPORHOST:site}
172.x.x.x -> %{WORD:method}
GET -> %{URIPATH:page}
/healthmonitor.axd -> %{NOTSPACE:querystring}
- -> %{NUMBER:port}
80 -> %{NOTSPACE:username}
- -> %{IPORHOST:clienthost}
172.x.x.x -> %{NOTSPACE:useragent}
HTTP/1.1 -> %{NOTSPACE:referer}
- -> %{NUMBER:response}
- -> %{NUMBER:subresponse}
- -> %{NUMBER:scstatus}
www.xyz.net -> %{NUMBER:bytes:int}
200 -> %{NUMBER:timetaken:int}
0 -> ?
0 -> ?
4698 -> ?
122 -> ?
703\r -> ?

```

You may also need to use a mutate filter to remove the training '\r' unless you account for that in the grok expression.

---

<div class="post-metadata">

**Author:** ![jack8653](https://avatars.discourse-cdn.com/v4/letter/j/9de0a6/32.png) [@jack8653](https://discuss.elastic.co/u/jack8653)\
**Post date:** [March 29, 2016, 7:17am UTC](https://discuss.elastic.co/t/logstash-2-2-2-windows-iis-log-file-format/45501/4 "2016-03-29T07:17:33Z")

</div>

Hi Christian,  
I've applied same above grock expression but still I'm getting same message [0] "\_grokparsefailure" error.

Here is my log file  
#Fields: date time s-sitename s-computername s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs-version cs(User-Agent) cs(Cookie) cs(Referer) cs-host sc-status sc-substatus sc-win32-status sc-bytes cs-bytes time-taken  
2016-03-25 00:00:01 W3SVC20 SANDBOXWEB01 172.30.34.167 GET /healthmonitor.axd - 80 - 172.30.34.4 HTTP/1.1 - - - [www.uk.sandbox.orderdynamics.net](http://www.uk.sandbox.orderdynamics.net) 200 0 0 4375 122 31  
2016-03-25 00:00:01 W3SVC20 SANDBOXWEB01 172.30.34.167 GET /healthmonitor.axd - 80 - 172.30.34.4 HTTP/1.1 - - - www.-uk.sandbox.orderdynamics.net 200 0 0 4374 122 15

Below is my logstash.conf  
input {  
file {  
type =\> "IISLog"  
path =\> "C:\IISLogs\u\_ex160324.log"  
start\_position =\> "beginning"  
}  
}

filter {

#ignore log comments  
if [message] =~ "^#" {  
drop {}  
}

grok {  
match =\> ["message",  
"%{TIMESTAMP\_ISO8601:log\_timestamp}  
%{WORD:iisSite}  
%{HOSTNAME}  
%{IPORHOST:site}  
%{WORD:method}  
%{URIPATH:page}  
%{NOTSPACE:querystring}  
%{NUMBER:port}  
%{NOTSPACE:username}  
%{IPORHOST:clienthost}  
HTTP/%{NUMBER:httpversion}  
%{NOTSPACE:referer}  
%{NOTSPACE:querystring}  
%{NOTSPACE:querystring}  
%{NUMBER:response}  
%{NUMBER:bytes:int}  
%{NUMBER:bytes:int}  
%{NUMBER:bytes:int}  
%{NUMBER:bytes:int}  
%{NUMBER:bytes:int}  
%{NUMBER:bytes:int}"]  
}

```
useragent {
	source=> "useragent"
	prefix=> "browser"
}

```

}

# output logs to console and to elasticsearch

output {  
stdout {}  
elasticsearch {  
hosts =\> ["127.0.0.1:9200"]  
}  
stdout { codec =\> rubydebug }  
}

---

<div class="post-metadata">

**Author:** ![jack8653](https://avatars.discourse-cdn.com/v4/letter/j/9de0a6/32.png) [@jack8653](https://discuss.elastic.co/u/jack8653)\
**Post date:** [March 30, 2016, 4:50am UTC](https://discuss.elastic.co/t/logstash-2-2-2-windows-iis-log-file-format/45501/5 "2016-03-30T04:50:18Z")

</div>

Hi Team,

Any update for above comment.

Thanks  
J

---

<div class="post-metadata">

**Author:** ![jack8653](https://avatars.discourse-cdn.com/v4/letter/j/9de0a6/32.png) [@jack8653](https://discuss.elastic.co/u/jack8653)\
**Post date:** [March 31, 2016, 5:24am UTC](https://discuss.elastic.co/t/logstash-2-2-2-windows-iis-log-file-format/45501/6 "2016-03-31T05:24:56Z")

</div>

Hi Christian,

If you shade some light. It will be help full.

Thanks  
J

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 31, 2016, 6:48am UTC](https://discuss.elastic.co/t/logstash-2-2-2-windows-iis-log-file-format/45501/7 "2016-03-31T06:48:17Z")

</div>

Don't break the grok pattern up into multiple lines. I just did choose to display it that way to show how fields did not match up. You are also capturing the `bytes` and `querystring` fields multiple times. I suspect this should be different fields. The general recommendation when building grok expressions is to start from the beginning and add field by field.

You also do not seem to be capturing the `useragent` field that you are trying to use in the user agent filter.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:04am UTC](https://discuss.elastic.co/t/logstash-2-2-2-windows-iis-log-file-format/45501/8 "2017-07-06T05:04:36Z")

</div>


