# Parsing IIS logs having two different format

**URL:** <https://discuss.elastic.co/t/parsing-iis-logs-having-two-different-format/100779>\
**Category:** Logstash\
**Created:** [September 17, 2017, 4:39am UTC](https://discuss.elastic.co/t/parsing-iis-logs-having-two-different-format/100779 "2017-09-17T04:39:48Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![kitex](https://avatars.discourse-cdn.com/v4/letter/k/f14d63/32.png) [@kitex](https://discuss.elastic.co/u/kitex)\
**Post date:** [September 17, 2017, 4:39am UTC](https://discuss.elastic.co/t/parsing-iis-logs-having-two-different-format/100779/1 "2017-09-17T04:39:49Z")

</div>

I have iss giving logs in below format:

```
September 16th 2017, 20:24:50.440	6.22.40.176 - - [14/Jul/2017:08:34:57 +0545] "GET /erport.aspx HTTP/1.1" 200 875
September 16th 2017, 20:24:50.440	2017-09-15 23:40:41 W3SVC2 WIN-JKLSIPLS 172.16.40.87 GET /erport.aspx - 80 - 23.16.82.25 ANDROID/9AppsClient/84/3.0.5.6/805/SM-G7102/4.4.2/19/720x1280 - appmango.com.hk 200 0 0 2

```

How to create rule to match both of the log lines?

I am trying using:

```
grok {
          match => ["message", "%{TIMESTAMP_ISO8601:log_timestamp} %{IPORHOST:site} %{WORD:method} %{URIPATH:page} %{NOTSPACE:querystring} %{NUMBER:port} %{NOTSPACE:username} %{IPORHOST:clienthost} %{NOTSPACE:useragent} (%{URI:referer})? %{NUMBER:response} %{NUMBER:subresponse} %{NUMBER:scstatus} %{NUMBER:time_taken}"]
	   }
```

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 18, 2017, 1:28pm UTC](https://discuss.elastic.co/t/parsing-iis-logs-having-two-different-format/100779/2 "2017-09-18T13:28:44Z")

</div>

You can list multiple expressions in a single grok filter. There's a syntax example in the grok documentation.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 16, 2017, 1:28pm UTC](https://discuss.elastic.co/t/parsing-iis-logs-having-two-different-format/100779/3 "2017-10-16T13:28:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
