# Parsing iis log

**URL:** <https://discuss.elastic.co/t/parsing-iis-log/133700>\
**Category:** Logstash\
**Created:** [May 29, 2018, 2:36pm UTC](https://discuss.elastic.co/t/parsing-iis-log/133700 "2018-05-29T14:36:45Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![neo](https://avatars.discourse-cdn.com/v4/letter/n/9fc348/32.png) [@neo](https://discuss.elastic.co/u/neo)\
**Post date:** [May 29, 2018, 2:36pm UTC](https://discuss.elastic.co/t/parsing-iis-log/133700/1 "2018-05-29T14:36:45Z")

</div>

I am new to grok function, can someone you help me to work this out  
my log look like :

#Software: Microsoft Internet Information Services 7.5  
#Version: 1.0  
#Date: 2018-04-25 00:00:00  
#Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken  
2018-04-25 00:00:00 100.00.0.00 HEAD / - 80 - 00.00.0.0 WhatsUp/0.0 - 1 1 1 62

and my conf file look like

input {  
beats {  
port =\> 5044  
type =\> "log"  
}  
}  
filter {  
mutate {  
add\_field =\> {  
"log\_timestamp" =\> "%{date} %{time}"  
}  
}  
}

grok {  
match =\> {"message" =\> "%{TIMESTAMP\_ISO8601:log\_timestamp}%{SPACE}%{IPORHOST:s-ip}%{SPACE}%{WORD:cs-method}%{SPACE}%{URIPATH:cs-uri-stem}%{SPACE}%{IPORHOST:c-ip}%{SPACE}%{NOTSPACE:cs-(User-Agent)}%{SPACE}%{WORD:sc(Referer)}%{SPACE}%{NUMBER:sc-status}%{SPACE}%{NUMBER:sc-substatus}%{SPACE}%{NUMBER:sc-win32-status}%{SPACE}%{NUMBER:time-taken}"  
}  
}  
}  
output {  
elasticsearch {  
hosts =\> "localhost:9200"  
manage\_template =\> false  
index =\> "iis\_test1-%{+YYYY.MM}"  
document\_type =\> "log"  
}  
}

the massage do't parsed, I'm getting one field  
t message 2018-05-01 23:58:49 172.18.1.23 GET /F5/F5.htm - 443 - 00.04.10.00 - - 200 0 0 0

---

<div class="post-metadata">

**Author:** ![guyboertje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guyboertje/32/31592_2.png) [@guyboertje](https://discuss.elastic.co/u/guyboertje)\
**Post date:** [May 29, 2018, 8:31pm UTC](https://discuss.elastic.co/t/parsing-iis-log/133700/2 "2018-05-29T20:31:14Z")

</div>

You can use Dissect, its better suited to log lines of very regular shape.

Notes:  
Try not to use field names like `cs-(User-Agent)` with parentheses.  
I simply took the `#Fields` line and put `%{` and `}` on either side of the field. I replaced the cs-(User-Agent) with cs-user-agent and used %{log\_timestamp} %{+log\_timestamp} instead of `date` and `time`.

```auto
input {
  generator {
    lines => [
      "2018-04-25 00:00:00 100.00.0.00 HEAD / - 80 - 00.00.0.0 WhatsUp/0.0 - 1 1 1 62",
      "2018-05-01 23:58:49 172.18.1.23 GET /F5/F5.htm - 443 - 00.04.10.00 - - 200 0 0 0"
    ]
    count => 1
  }
}

filter {
  dissect {
    mapping => {
      message => '%{log_timestamp} %{+log_timestamp} %{s-ip} %{cs-method} %{cs-uri-stem} %{cs-uri-query} %{s-port} %{cs-username} %{c-ip} %{cs-user-agent} %{cs-referer} %{sc-status} %{sc-substatus} %{sc-win32-status} %{time-taken}'
    }
  }
}

output {
  stdout {
    codec => rubydebug
  }
}

```

Gives

```auto
{
             "s-port" => "443",
       "cs-uri-query" => "-",
    "sc-win32-status" => "0",
            "message" => "2018-05-01 23:58:49 172.18.1.23 GET /F5/F5.htm - 443 - 00.04.10.00 - - 200 0 0 0",
               "c-ip" => "00.04.10.00",
               "s-ip" => "172.18.1.23",
        "cs-uri-stem" => "/F5/F5.htm",
        "cs-username" => "-",
           "@version" => "1",
         "cs-referer" => "-",
           "sequence" => 0,
               "host" => "Elastics-MacBook-Pro.local",
      "cs-user-agent" => "-",
       "sc-substatus" => "0",
         "time-taken" => "0",
      "log_timestamp" => "2018-05-01 23:58:49",
          "cs-method" => "GET",
         "@timestamp" => 2018-05-29T20:25:17.199Z,
          "sc-status" => "200"
}
{
             "s-port" => "80",
       "cs-uri-query" => "-",
    "sc-win32-status" => "1",
            "message" => "2018-04-25 00:00:00 100.00.0.00 HEAD / - 80 - 00.00.0.0 WhatsUp/0.0 - 1 1 1 62",
               "c-ip" => "00.00.0.0",
               "s-ip" => "100.00.0.00",
        "cs-uri-stem" => "/",
        "cs-username" => "-",
           "@version" => "1",
         "cs-referer" => "-",
           "sequence" => 0,
               "host" => "Elastics-MacBook-Pro.local",
      "cs-user-agent" => "WhatsUp/0.0",
       "sc-substatus" => "1",
         "time-taken" => "62",
      "log_timestamp" => "2018-04-25 00:00:00",
          "cs-method" => "HEAD",
         "@timestamp" => 2018-05-29T20:25:17.174Z,
          "sc-status" => "1"
}

```

---

<div class="post-metadata">

**Author:** ![neo](https://avatars.discourse-cdn.com/v4/letter/n/9fc348/32.png) [@neo](https://discuss.elastic.co/u/neo)\
**Post date:** [May 30, 2018, 6:28am UTC](https://discuss.elastic.co/t/parsing-iis-log/133700/3 "2018-05-30T06:28:05Z")

</div>

@guyboertje, thank you so mach, it work great.

---

<div class="post-metadata">

**Author:** ![guyboertje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guyboertje/32/31592_2.png) [@guyboertje](https://discuss.elastic.co/u/guyboertje)\
**Post date:** [May 30, 2018, 7:47am UTC](https://discuss.elastic.co/t/parsing-iis-log/133700/4 "2018-05-30T07:47:28Z")

</div>

Make sure you check any previous logs for a `cs-uri-query` value that is not Percent encoded. If a space leaks into that value the mapping will not give the correct results. e.g. should be `foo%20bar` and not `foo bar`.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 27, 2018, 7:47am UTC](https://discuss.elastic.co/t/parsing-iis-log/133700/5 "2018-06-27T07:47:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
