I was using nxlog to send windows and iis logs to Graylog successfully for about 2 years. I rebooted my Graylog server after some updates, and now all my IIS servers are not sending logs. I am getting errors relating to parsing time. So, I decided to try to use the Sidecar with Filebeat to get my IIS logs into Graylog. I am using the collector_sidecar_installer_0.1.7-1.exe installer, which seems to bundle Filebeat 6.4.1.
Filebeat is picking up the logs and sending them to Graylog, but they are not nicely parsed the way nxlog used to do it. I read on the Filebeat site that there is an IIS module. I added the following Beats snippet:
- module: iis
- module: system
The snippet above resulted in me sending the IIS logs to Graylog, but they are not parsed as mentioned above.
The full filebeat.yml file that is created by the sidecar is:
I could not do add the iis module without configuring filebeat.config.modules section. When I tried to add some additional options under -module: iis, the filebeat would not start.
Does anybody know how to get filebeat to actually parse the IIS logs?