# Logstash.yml to collect IIS logs with filebeat error

**URL:** <https://discuss.elastic.co/t/logstash-yml-to-collect-iis-logs-with-filebeat-error/135066>\
**Category:** Logstash\
**Created:** [June 8, 2018, 12:04am UTC](https://discuss.elastic.co/t/logstash-yml-to-collect-iis-logs-with-filebeat-error/135066 "2018-06-08T00:04:31Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![alexserd](https://avatars.discourse-cdn.com/v4/letter/a/f17d59/32.png) [@alexserd](https://discuss.elastic.co/u/alexserd)\
**Post date:** [June 8, 2018, 12:04am UTC](https://discuss.elastic.co/t/logstash-yml-to-collect-iis-logs-with-filebeat-error/135066/1 "2018-06-08T00:04:31Z")

</div>

Getting error trying to start logstash with following config file  
.\logstash.bat -f logstash.yml

LOGSTASH.YML

# 

input {  
beats {  
port =\> 5044  
type =\> 'iis'  
}  
}

filter {

## Ignore the comments that IIS will add to the start of the W3C logs

# 

if [message] =~ "^#" {  
drop {}  
}

grok {  
## Very helpful site for building these statements:  
# [http://grokdebug.herokuapp.com/](http://grokdebug.herokuapp.com/)  
#  
# This is configured to parse out every field of IIS's W3C format when  
# every field is included in the logs  
#  
match =\> ["message", "%{TIMESTAMP\_ISO8601:log\_timestamp} %{WORD:serviceName} %{WORD:serverName} %{IP:serverIP} %{WORD:method} %{URIPATH:uriStem} %{NOTSPACE:uriQuery} %{NUMBER:port} %{NOTSPACE:username} %{IPORHOST:clientIP} %{NOTSPACE:protocolVersion} %{NOTSPACE:userAgent} %{NOTSPACE:cookie} %{NOTSPACE:referer} %{NOTSPACE:requestHost} %{NUMBER:response} %{NUMBER:subresponse} %{NUMBER:win32response} %{NUMBER:bytesSent} %{NUMBER:bytesReceived} %{NUMBER:timetaken}"]  
}  
date {  
match =\> ["timestamp", "yyyy-MM-dd HH:mm:ss"]  
locale =\> "en"  
}  
}

# Second filter

filter {  
if "\_grokparsefailure" in [tags] {

```
} else {
# on success remove the message field to save space
mutate {
  remove_field => ["message", "timestamp"]
}

```

}  
}

output {  
elasticsearch {  
hosts =\> ["sna-wsus01:9200"]  
index =\> "logstash-%{+YYYY.MM.dd}"  
template =\> "./conf/logstash-template.json"  
template\_name =\> "logstash"  
document\_type =\> "iis"  
template\_overwrite =\> true  
manage\_template =\> true  
}  
}

FILEBEAT.YML

filebeat.prospectors:

- type: log  
enabled: false  
paths:  
- C:\inetpub\logs\LogFiles\W3SVC1296615932\*  
filebeat.config.modules:  
path: ${path.config}/modules.d/\*.yml  
reload.enabled: false  
setup.template.settings:  
index.number\_of\_shards: 3  
setup.kibana:  
output.elasticsearch:  
hosts: ["sna-wsus01:5044"]

ERROR

PS D:\Elastic\Logstash\bin\> .\logstash.bat  
Sending Logstash's logs to D:/Elastic/Logstash/logs which is now configured via log4j2.properties  
[2018-06-07T16:43:08,751][INFO][logstash.modules.scaffold] Initializing module {:module\_name=\>"fb\_apache", :directory=\>  
"D:/Elastic/Logstash/modules/fb\_apache/configuration"}  
[2018-06-07T16:43:09,052][INFO][logstash.modules.scaffold] Initializing module {:module\_name=\>"netflow", :directory=\>"D  
:/Elastic/Logstash/modules/netflow/configuration"}  
[2018-06-07T16:43:09,318][FATAL][logstash.runner] An unexpected error occurred! {:error=\>#\<ArgumentError: Sett  
ing "" hasn't been registered\>, :backtrace=\>["D:/Elastic/Logstash/logstash-core/lib/logstash/settings.rb:37:in `get_sett ing'", "D:/Elastic/Logstash/logstash-core/lib/logstash/settings.rb:70:in`set\_value'", "D:/Elastic/Logstash/logstash-cor  
e/lib/logstash/settings.rb:89:in `block in merge'", "org/jruby/RubyHash.java:1343:in`each'", "D:/Elastic/Logstash/logst  
ash-core/lib/logstash/settings.rb:89:in `merge'", "D:/Elastic/Logstash/logstash-core/lib/logstash/settings.rb:138:in`va  
lidate\_all'", "D:/Elastic/Logstash/logstash-core/lib/logstash/runner.rb:264:in `execute'", "D:/Elastic/Logstash/vendor/b undle/jruby/2.3.0/gems/clamp-0.6.5/lib/clamp/command.rb:67:in`run'", "D:/Elastic/Logstash/logstash-core/lib/logstash/ru  
nner.rb:219:in `run'", "D:/Elastic/Logstash/vendor/bundle/jruby/2.3.0/gems/clamp-0.6.5/lib/clamp/command.rb:132:in`run'  
", "D:\Elastic\Logstash\lib\bootstrap\environment.rb:67:in `'"]}  
[2018-06-07T16:43:09,349][ERROR][org.logstash.Logstash] java.lang.IllegalStateException: org.jruby.exceptions.RaiseE  
xception: (SystemExit) exit

2nd question is there a IIS Module that needs to be installed for Logstash?

I was able to setup ELK stack for collecting Windows Event Logs with Winlogbeat but having issues with IIS

Thanks!

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 8, 2018, 5:44am UTC](https://discuss.elastic.co/t/logstash-yml-to-collect-iis-logs-with-filebeat-error/135066/2 "2018-06-08T05:44:31Z")

</div>

Seems to be a problem with your logstash.yml. Please post it and **make sure you format it as preformatted text using Markdown notation or the `</>` toolbar button**.

> 2nd question is there a IIS Module that needs to be installed for Logstash?

No.

---

<div class="post-metadata">

**Author:** ![alexserd](https://avatars.discourse-cdn.com/v4/letter/a/f17d59/32.png) [@alexserd](https://discuss.elastic.co/u/alexserd)\
**Post date:** [June 8, 2018, 4:30pm UTC](https://discuss.elastic.co/t/logstash-yml-to-collect-iis-logs-with-filebeat-error/135066/3 "2018-06-08T16:30:02Z")

</div>

Magnus, the logstash.yml file is above

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 9, 2018, 8:23am UTC](https://discuss.elastic.co/t/logstash-yml-to-collect-iis-logs-with-filebeat-error/135066/4 "2018-06-09T08:23:51Z")

</div>

You posted a _pipeline configuration file_ that you for some reason have named logstash.yml. That's the standard name for Logstash's _settings file_, which is a different file. Logstash isn't starting up because it's having problems loading the settings file, so it's probably getting hold of your pipeline configuration file.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 7, 2018, 8:23am UTC](https://discuss.elastic.co/t/logstash-yml-to-collect-iis-logs-with-filebeat-error/135066/5 "2018-07-07T08:23:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
