# Remote IIS logs into ELK Stack?

**URL:** <https://discuss.elastic.co/t/remote-iis-logs-into-elk-stack/47157>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [April 12, 2016, 5:46pm UTC](https://discuss.elastic.co/t/remote-iis-logs-into-elk-stack/47157 "2016-04-12T17:46:21Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Phil\_Austin](https://avatars.discourse-cdn.com/v4/letter/p/bbce88/32.png) [@Phil\_Austin](https://discuss.elastic.co/u/Phil_Austin)\
**Post date:** [April 12, 2016, 5:46pm UTC](https://discuss.elastic.co/t/remote-iis-logs-into-elk-stack/47157/1 "2016-04-12T17:46:21Z")

</div>

Hi, I have to first apologize for my ignorance as i JUST configured my ELK setup and am getting familiar with the technology, Here is my issue... I would like to ship logs from a dozen or so IIS servers to my Log server which is utilizing Elasticsearch, Logstash and Kibana. I can't seem to find the right documentation on how to get those IIS logs visible and searchable in Kibana. I understand that I'll need to use filebeat but unsure of what additional configuration is needed to get it to work appropriately. Any assistance would be greatly appreciated!

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [April 12, 2016, 5:58pm UTC](https://discuss.elastic.co/t/remote-iis-logs-into-elk-stack/47157/2 "2016-04-12T17:58:09Z")

</div>

I would recommend following the [Getting Started](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-getting-started.html) guide for Filebeat. First ship your logs directly to Elasticsearch for learning purposes. Then add [Logstash](https://www.elastic.co/guide/en/beats/libbeat/1.2/logstash-installation.html#logstash-setup) to the mix (Filebeat -\> Logstash -\> Elasticsearch) to do some [grok](https://www.elastic.co/guide/en/logstash/current/plugins-filters-grok.html) parsing on your log messages.

---

<div class="post-metadata">

**Author:** ![Phil\_Austin](https://avatars.discourse-cdn.com/v4/letter/p/bbce88/32.png) [@Phil\_Austin](https://discuss.elastic.co/u/Phil_Austin)\
**Post date:** [April 19, 2016, 5:09pm UTC](https://discuss.elastic.co/t/remote-iis-logs-into-elk-stack/47157/4 "2016-04-19T17:09:31Z")

</div>

I have it pulling logs locally without issue. But I seem to be having issues when attempting to get the IIS logs from my other web servers. I'd be happy to show config files if that'd help. I'm so new to this that I'm unsure at this point what would help troubleshooting. Thanks!

---

<div class="post-metadata">

**Author:** ![Dave\_Murphy](https://avatars.discourse-cdn.com/v4/letter/d/a9adbd/32.png) [@Dave\_Murphy](https://discuss.elastic.co/u/Dave_Murphy)\
**Post date:** [October 18, 2016, 11:51pm UTC](https://discuss.elastic.co/t/remote-iis-logs-into-elk-stack/47157/5 "2016-10-18T23:51:33Z")

</div>

My issue is I have a filebeats input on my elk stack. I have a syslog filter which works great. I setup an IIS filter. The pattern passes the grok filter when I test via [https://grokdebug.herokuapp.com/](https://grokdebug.herokuapp.com/), however, when I attempt to pull the data in Kibana, I'm getting issues with the grok parsing. I can see the fields in the kibana filebeat settings, so they seem to be imported correctly. Here is a sample of my "iis" filter:

filter {  
if [type] == "iis" {  
grok {

pattern =\> "%{DATESTAMP:EventTime} %{WORD:sitename} %{HOSTNAME:computername} %{IP:hostip} %{URIPROTO:method} %{URIPATH:request} (?:%{NOTSPACE:queryparam}|-) %{NUMBER:port} (?:%{WORD:username}|-) %{IP:clientip} %{NOTSPACE:httpversion} %{NOTSPACE:user-agent} (?:%{NOTSPACE:cookie}|-) (?:%{NOTSPACE:referer}|-) (?:%{HOSTNAME:host}|-) %{NUMBER:status} %{NUMBER:sub-status} %{NUMBER:win32-status} %{NUMBER:bytes-received} %{NUMBER:bytes-sent} %{NUMBER:time-taken}"

}

geoip {  
source =\> "clientip"  
target =\> "geoip"  
add\_tag =\> ["iis\_geoip"]  
}

date {

match=\> ["EventTime", "yyyy-MM-dd HH:mm:ss"]  
}  
}

}

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [October 19, 2016, 11:06am UTC](https://discuss.elastic.co/t/remote-iis-logs-into-elk-stack/47157/6 "2016-10-19T11:06:08Z")

</div>

@Dave_Murphy seems like you want to post your question in the logstash forum.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 9:50pm UTC](https://discuss.elastic.co/t/remote-iis-logs-into-elk-stack/47157/7 "2017-07-05T21:50:28Z")

</div>


