# .NET W3C format webserver access logs on Linux

**URL:** <https://discuss.elastic.co/t/net-w3c-format-webserver-access-logs-on-linux/382178>\
**Category:** Logs\
**Created:** [September 23, 2025, 6:13pm UTC](https://discuss.elastic.co/t/net-w3c-format-webserver-access-logs-on-linux/382178 "2025-09-23T18:13:23Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![taprove](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/taprove/32/146825_2.png) [@taprove](https://discuss.elastic.co/u/taprove)\
**Post date:** [September 23, 2025, 6:13pm UTC](https://discuss.elastic.co/t/net-w3c-format-webserver-access-logs-on-linux/382178/1 "2025-09-23T18:13:23Z")

</div>

Before I go down the path of creating something custom to bring in W3C format access logs generated from .NET https server apps on Linux, I wanted to make sure there wasn’t some easier way to do it with an existing integration.

The logs are the default setting with X-Forwarded-For, so they would be similar to what is collected from IIS, though they have a much different naming.

Any insight before I venture down the custom log path is greatly appreciated.

Thanks,  
Tim

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 24, 2025, 12:02am UTC](https://discuss.elastic.co/t/net-w3c-format-webserver-access-logs-on-linux/382178/2 "2025-09-24T00:02:05Z")

</div>

Hi @approve

Best way for us to help is post us a couple samples of the log lines...  
Most likely there is already something or something that's very close

---

<div class="post-metadata">

**Author:** ![taprove](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/taprove/32/146825_2.png) [@taprove](https://discuss.elastic.co/u/taprove)\
**Post date:** [September 24, 2025, 6:17pm UTC](https://discuss.elastic.co/t/net-w3c-format-webserver-access-logs-on-linux/382178/3 "2025-09-24T18:17:51Z")

</div>

Here is the header at beginning of log file showing fields, and a few creatively redacted lines (this is a dev box so the x-forwarded-for is just “-” but it contains an IP on prod boxes and is often populated from cf-connecting-ip rather than x-forward-for):

```auto
#Version: 1.0
#Start-Date: 2025-09-01 11:14:24
#Fields: date time c-ip cs-username s-computername s-ip s-port cs-method cs-uri-stem cs-uri-query sc-status time-taken cs-version cs-host cs(User-Agent) cs(Cookie) cs(Referer) cs(x-forwarded-for)
2025-09-01 11:14:21 10.0.0.1 - linuxbox 10.0.0.9 443 GET / - 200 1129.4752 HTTP/2 linuxbox.foo.com Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/139.0.0.0+Safari/537.36 - - -
2025-09-01 11:14:22 10.0.0.1 - linuxbox 10.0.0.9 443 GET /FOO_WEB.styles.css - 200 57.8247 HTTP/2 linuxbox.foo.com Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/139.0.0.0+Safari/537.36 - https://linuxbox.foo.com/ - 
2025-09-01 11:14:22 10.0.0.1 - linuxbox 10.0.0.9 443 GET /js/SomeJSFile.js - 200 52.1164 HTTP/2 linuxbox.foo.com Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/139.0.0.0+Safari/537.36 - https://linuxbox.foo.com/ -

```

Thanks!

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 25, 2025, 3:05pm UTC](https://discuss.elastic.co/t/net-w3c-format-webserver-access-logs-on-linux/382178/4 "2025-09-25T15:05:16Z")

</div>

Hi @taprove

So the closest Integration we have is the IIS integration, it matches a number of the most popular pattern

> **[IIS (Internet Information Services) integration | Elastic integrations](https://www.elastic.co/docs/reference/integrations/iis)**
>
> The IIS (Internet Information Services) integration allows you to monitor your IIS Web servers. IIS is a secure, reliable, and scalable Web server that...

It supports a number of patterns but unfortunately it does not appear to support your customer pattern.

I would suggest

A) Loading the integration and cloning the Ingest Pipeline and add a `GROK` pattern that matches your specific pattern.

or

B) Rearrange your output to match one of the OOTB patterns

C) Though not recommended you can edit the ingest pipeline from the integration but those changes will be overwritten if / when you upgrade the integration.

---

<div class="post-metadata">

**Author:** ![taprove](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/taprove/32/146825_2.png) [@taprove](https://discuss.elastic.co/u/taprove)\
**Post date:** [September 25, 2025, 3:22pm UTC](https://discuss.elastic.co/t/net-w3c-format-webserver-access-logs-on-linux/382178/5 "2025-09-25T15:22:06Z")

</div>

I can make the log match the pattern. After that would it be as simple as adding the Linux paths and patterns for the logs to the IIS Access Logs paths?

Thanks!

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 25, 2025, 3:38pm UTC](https://discuss.elastic.co/t/net-w3c-format-webserver-access-logs-on-linux/382178/6 "2025-09-25T15:38:12Z")

</div>

> [@taprove](#):
>
> I can make the log match the pattern. After that would it be as simple as adding the Linux paths and patterns for the logs to the IIS Access Logs paths?

Apologies ... I am not quite parsing 🙂

You will make the YOUR logs patterns match one of the supported Patterns for the Elastic IIS Integration?

---

<div class="post-metadata">

**Author:** ![taprove](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/taprove/32/146825_2.png) [@taprove](https://discuss.elastic.co/u/taprove)\
**Post date:** [September 25, 2025, 3:52pm UTC](https://discuss.elastic.co/t/net-w3c-format-webserver-access-logs-on-linux/382178/7 "2025-09-25T15:52:24Z")

</div>

My apologies, I could have been clearer. I can make the application log fields match our IIS logs that are being processed already.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 25, 2025, 5:02pm UTC](https://discuss.elastic.co/t/net-w3c-format-webserver-access-logs-on-linux/382178/8 "2025-09-25T17:02:14Z")

</div>

> [@taprove](#):
>
> I could have been clearer. I can make the application log fields match our IIS logs that are being processed already.

So matching your Application Logs to one of the Existing Supporting Patterns, then yes you can then use the IIS Integration and point it to the logs paths...

If you provide a few examples after you re-format I can show you how to do a quick test.

---

<div class="post-metadata">

**Author:** ![taprove](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/taprove/32/146825_2.png) [@taprove](https://discuss.elastic.co/u/taprove)\
**Post date:** [September 25, 2025, 7:01pm UTC](https://discuss.elastic.co/t/net-w3c-format-webserver-access-logs-on-linux/382178/9 "2025-09-25T19:01:15Z")

</div>

Excellent. I ‘ll work on getting the required changes into the code and generate a new log. It might be a little bit, but I’ll be back!

Thanks!

---

<div class="post-metadata">

**Author:** ![taprove](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/taprove/32/146825_2.png) [@taprove](https://discuss.elastic.co/u/taprove)\
**Post date:** [October 30, 2025, 1:34pm UTC](https://discuss.elastic.co/t/net-w3c-format-webserver-access-logs-on-linux/382178/10 "2025-10-30T13:34:00Z")

</div>

Just a follow up as I hate old threads where the OP just “vanished” with no “what I ended up doing” 😉

Turns out that the positioning of fields when using the W3C logging with the dotnet web stuff is not move-around-able. Would have had to write a custom middleware, and while it was originally my application when I was a dev, I’m in security now, not development, so I came up with a solution within Elastic.

What I ended up doing was building my first custom ingest pipeline to get my employer a little bit of return on the Elastic Observability Engineer training they (virtually) sent me to. 🤓

Put my learning to use and created an ingest pipeline with some cool stuff like adding cloudflare headers to the http.request object, and of course, all the proper handling of fields for ECS usage.

So in a way, I guess “no easy answer” led to me leaving my comfort zone, and now I’m eager to do more custom log stuff!
