# While sending iis logs from filebeat to logstash few feilds do not get populated

**URL:** <https://discuss.elastic.co/t/while-sending-iis-logs-from-filebeat-to-logstash-few-feilds-do-not-get-populated/225173>\
**Category:** Logstash\
**Created:** [March 26, 2020, 11:11am UTC](https://discuss.elastic.co/t/while-sending-iis-logs-from-filebeat-to-logstash-few-feilds-do-not-get-populated/225173 "2020-03-26T11:11:55Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sagar\_Joshi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sagar_joshi/32/65107_2.png) [@Sagar\_Joshi](https://discuss.elastic.co/u/Sagar_Joshi)\
**Post date:** [March 26, 2020, 11:11am UTC](https://discuss.elastic.co/t/while-sending-iis-logs-from-filebeat-to-logstash-few-feilds-do-not-get-populated/225173/1 "2020-03-26T11:11:55Z")

</div>

While sending IIS logs from filebeat --\> Logstash --\> ElasticSearch --\> Kibana , we lose couple of fields like (user\_agent and geo location ) even after applying GROK pattern inside logstash FILTER.

Hence couple of visualization (access map , browser breakdown) in IIS default dashboard do not show any data.

We have to send IIS logs to logstash ( and not directly to ElasticSearch) because we also need to send application logs from filebeat to logstash from same server ( and we can send log to EITHER logstash or elastic search only)

So , do you know any way to pull useragent and geoip fields ?

The only other way we know is to configure 2 filebeat on client (application servers ).

**Filebeat\_IIS**

It will send IIS logs to Elastic search ( and NOT through logstash )

**Filebeat\_applogs**

It will send application logs to logstash (where we will apply grok pattern ) and then to Elastic search

We tried installing below plugins in logstash  
bin\logstash-plugin install logstash-filter-useragent  
bin\logstash-plugin install logstash-filter-geoip

But still it does not show DATA in following fields in kibana index pattern  
**source.geoip**  
**source.geo.location**

**user\_agent.name**  
**user\_agent.version**  
**user\_agent.os.name**  
**user\_agent.os.version**

Please let me know if you have any solution

FIlebeat , Kibana , Logstash and Elastic Search ( all on v 7.5.1)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 23, 2020, 11:11am UTC](https://discuss.elastic.co/t/while-sending-iis-logs-from-filebeat-to-logstash-few-feilds-do-not-get-populated/225173/2 "2020-04-23T11:11:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
