# Trying to setup Filebeat to send IIS logs to logstash

**URL:** <https://discuss.elastic.co/t/trying-to-setup-filebeat-to-send-iis-logs-to-logstash/198086>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [September 4, 2019, 5:46pm UTC](https://discuss.elastic.co/t/trying-to-setup-filebeat-to-send-iis-logs-to-logstash/198086 "2019-09-04T17:46:15Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![sonammarda](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sonammarda/32/52241_2.png) [@sonammarda](https://discuss.elastic.co/u/sonammarda)\
**Post date:** [September 4, 2019, 5:46pm UTC](https://discuss.elastic.co/t/trying-to-setup-filebeat-to-send-iis-logs-to-logstash/198086/1 "2019-09-04T17:46:15Z")

</div>

_Filebeat version_- 7.3  
_Logstash version_- 7.3  
_OS_- Windows

Filebeat.yml file-  
filebeat.inputs:

- type: log  
enabled: true

filebeat.config.modules:  
#Glob pattern for configuration loading  
path: ${path.config}/modules.d/\*.yml

#Set to true to enable config reloading  
reload.enabled: false

#==================== Elasticsearch template setting ==========================

setup.template.settings:  
index.number\_of\_shards: 1

name:  
#The tags of the shipper are included in their own field with each  
#transaction published.  
tags: ["esm-purchase-api-log"]

output.logstash:  
hosts: ["localhost:5044"]

processors:

- add\_host\_metadata: ~
- add\_cloud\_metadata: ~

Logstash config file:  
input {  
beats{  
port=\>5044  
}  
}  
output {  
if "esm-purchase-api-log" in [tags] {  
elasticsearch {  
hosts =\> ["localhost:9200"]  
index =\> "esm-purchase-api-log-%{+YYYY.MM.dd}"  
}  
}  
}

But it does not create any index as specified in logstash config file. Also I do not see any data reading my application logs.

However, if I directly set output of my filebeat to elasticsearch, then it starts reading my data under filebeat-\* common index. However, I want to create different index for different types of files(application log files, iis log files, etc.) I am sending through filebeat. And I want to achieve it with below kind of setup:  
Filebeat-\> Logstash -\> ElasticSerach -\>Kibana

I have also enabled logstash in filebeat using command - filebeat.exe modules enable logstash. I do not want to enable iis.yml module in filebeat. I want to specify path to pick iis log files as I have done above in code.

Any help appreciated!

---

<div class="post-metadata">

**Author:** ![sonammarda](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sonammarda/32/52241_2.png) [@sonammarda](https://discuss.elastic.co/u/sonammarda)\
**Post date:** [September 6, 2019, 11:08am UTC](https://discuss.elastic.co/t/trying-to-setup-filebeat-to-send-iis-logs-to-logstash/198086/2 "2019-09-06T11:08:38Z")

</div>

This is working fine now. It was taking time to create index.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 4, 2019, 11:12am UTC](https://discuss.elastic.co/t/trying-to-setup-filebeat-to-send-iis-logs-to-logstash/198086/3 "2019-10-04T11:12:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
