# Logstash not filtering IIS message into fields in Kibana

**URL:** <https://discuss.elastic.co/t/logstash-not-filtering-iis-message-into-fields-in-kibana/165157>\
**Category:** Logstash\
**Created:** [January 22, 2019, 6:13am UTC](https://discuss.elastic.co/t/logstash-not-filtering-iis-message-into-fields-in-kibana/165157 "2019-01-22T06:13:36Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Shafiq](https://avatars.discourse-cdn.com/v4/letter/s/f05b48/32.png) [@Shafiq](https://discuss.elastic.co/u/Shafiq)\
**Post date:** [January 22, 2019, 6:13am UTC](https://discuss.elastic.co/t/logstash-not-filtering-iis-message-into-fields-in-kibana/165157/1 "2019-01-22T06:13:36Z")

</div>

Hi There,  
I have setup Elasticsearch, Logstash, Kibana and filebeat 6.5.4 version on Windows server 2012 R2. I have configured Filebeat to collect the logs of IIS and send to logstash.  
In kibana I can see the IIS logs but im not able to filter “message” using grok filtering. Below is the configuration of Filebeat, Logstash

\</\> filebeat.prospectors:

- type: log  
enabled: true  
paths:  
#- /var/log/\*.log  
#- c:\programdata\elasticsearch\logs\*

\</\> LogStash cong file (this file is in D:\logstash-6.5.4\bin)  
input {  
beats {  
port =\> 5044  
type =\> "iis"  
}  
}  
output {  
elasticsearch {  
hosts =\> "192.168.1.12:9200"  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
document\_type =\> "%{[@metadata][type]}"  
}  
}

\</\> Input.conf ( input configuration file)  
input {  
beats {  
file {  
path =\> "C:\inetpub\logs\LogFiles\*\*"  
type =\> iis  
port =\> 5044  
}  
}

\</\> IIS filter configuration  
filter {  
if [type] ==\> "iis" {  
grok {  
match =\> { "message" =\> "%{TIMESTAMP\_ISO8601:log\_timestamp}\s%{IPORHOST:S-IP}\s%{WORD:CS-Method}\s%{URIPATH:CS-URI-Stem} (?:-|"%{URIPATH:CS-URI-Query}")\s%{NUMBER:SERVER-Port} %{NOTSPACE:CS-Username}\s%{IPORHOST:CLIENT-IP}\s%{NOTSPACE:CS-UserAgent}\s%{NOTSPACE:CS-Referer}\s%{NOTSPACE:CS-Host}\s%{NUMBER:SC-Status} %{NUMBER:SC-SubStatus} %{NUMBER:SC-Win32-Status} %{NUMBER:SC-Bytes} %{NUMBER:CS-Bytes} %{NUMBER:Time-Taken}"}  
}  
}  
}

\</\> Elasticsearch Output configuration file  
output {  
elasticsearch {  
hosts =\> ["192.168.1.12:9200"]  
sniffing =\> true  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
document\_type =\> "%{[@metadata][type]}"  
}  
}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 22, 2019, 1:21pm UTC](https://discuss.elastic.co/t/logstash-not-filtering-iis-message-into-fields-in-kibana/165157/2 "2019-01-22T13:21:46Z")

</div>

What does an input line look like?

---

<div class="post-metadata">

**Author:** ![Shafiq](https://avatars.discourse-cdn.com/v4/letter/s/f05b48/32.png) [@Shafiq](https://discuss.elastic.co/u/Shafiq)\
**Post date:** [January 23, 2019, 6:26am UTC](https://discuss.elastic.co/t/logstash-not-filtering-iis-message-into-fields-in-kibana/165157/3 "2019-01-23T06:26:50Z")

</div>

Thanks badger for the reply...

input {  
beats {  
file {  
type =\> iis  
port =\> 5044  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 23, 2019, 2:36pm UTC](https://discuss.elastic.co/t/logstash-not-filtering-iis-message-into-fields-in-kibana/165157/4 "2019-01-23T14:36:22Z")

</div>

Not the input configuration, what does one line of the IIS log look like?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 20, 2019, 2:36pm UTC](https://discuss.elastic.co/t/logstash-not-filtering-iis-message-into-fields-in-kibana/165157/5 "2019-02-20T14:36:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
