# Send IIS logs with Filebeat to ElasticSearch

**URL:** <https://discuss.elastic.co/t/send-iis-logs-with-filebeat-to-elasticsearch/167152>\
**Category:** Elasticsearch\
**Created:** [February 5, 2019, 3:24pm UTC](https://discuss.elastic.co/t/send-iis-logs-with-filebeat-to-elasticsearch/167152 "2019-02-05T15:24:19Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Roan](https://avatars.discourse-cdn.com/v4/letter/r/e19b73/32.png) [@Roan](https://discuss.elastic.co/u/Roan)\
**Post date:** [February 5, 2019, 3:24pm UTC](https://discuss.elastic.co/t/send-iis-logs-with-filebeat-to-elasticsearch/167152/1 "2019-02-05T15:24:20Z")

</div>

Hi, I could use some advice. I'm a newbee on filebeat and could use your help.  
I'm trying to send IIS log files with filebeat to ElasticSearch. But it's not working as how I would like it to do. 🤔

I've a problem with Filebeat not sending messages to an AWS ES when using the IIS module.  
ES on AWS is a service based solution and we're not able to install the ingest-geoip plugin on it.  
Also we're not interested is the geographical features. We are interested in the urls's especially.

Our setup is like this:  
IIS webservice (Windows Server 2012) --\> Filebeat 6.6.0 --\> ES (AWS) 5.6.8

I've ran the setup step. This step creates the filebeat index. I also see that the fields that I need are created but these fields are not populated by filebeat.  
The connection to ES does not give an error. The template is also created.  
But when I start filebeat I get the following error:

```
ERROR pipeline/output.go:100 Failed to connect to backoff(elasticsearch(https://logging.phoenix.wehkamp.prod.blaze.ps:443)):
Connection marked as failed because the onConnect callback failed: Error loading
 pipeline for fileset iis/access: This module requires the following Elasticsearch plugins: ingest-geoip. You can install them by running the following commands on all the Elasticsearch nodes:
    sudo bin/elasticsearch-plugin install ingest-geoip

```

Is there a way to use the IIS module logic without the ingest-geoip plugin?  
Or do we need to implement it in another way?

Below is my config file:

```
filebeat.inputs:
#- type: log
# enabled: true
# paths:
# - 'C:\inetpub\logs\LogFiles\W3SVC1\*.log'
filebeat.config:
  #inputs:
    #enabled: false
    #path: inputs.d/*.yml
    #reload.enabled: true
    #reload.period: 10s
  modules:
    enabled: true
    path: modules.d/*.yml
    #reload.enabled: true
    #reload.period: 10s
  
output.elasticsearch:
  hosts: ["https://SERVER:443"]
  protocol: "https"
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 5, 2019, 3:24pm UTC](https://discuss.elastic.co/t/send-iis-logs-with-filebeat-to-elasticsearch/167152/2 "2019-03-05T15:24:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
