Skip to content

Instantly share code, notes, and snippets.

@aensidhe
Created May 27, 2015 08:52
Show Gist options
  • Save aensidhe/e8069dd159cdd86c97fa to your computer and use it in GitHub Desktop.
Save aensidhe/e8069dd159cdd86c97fa to your computer and use it in GitHub Desktop.
IIS full log grok pattern
IISDATE %{YEAR}-%{MONTHNUM}-%{MONTHDAY}
IISURIPARAM [A-Za-z0-9$.+!*'|(){},~@#%&/=:;_?\-\[\]]*
IISHOST %{IPORHOST}(:%{POSINT})?
IISURL (%{URIPROTO}://%{IISHOST}?%{URIPATHPARAM}?)|\-
IISTIMESTAMP %{IISDATE} %{TIME}
IISLOG %{IISTIMESTAMP:datetime} %{NOTSPACE:site} %{HOSTNAME:server} %{IP:server_ip} %{WORD:http_method} %{URIPATHPARAM:url_path} %{IISURIPARAM:url_query} %{POSINT:port:int} %{NOTSPACE:user} %{IP:client_ip} %{NOTSPACE:http_version} %{NOTSPACE:user_agent} %{NOTSPACE:cookies} %{IISURL:referer} %{IISHOST:host_name} %{INT:http_status:int} %{INT:http_sub_status:int} %{INT:win32_status:int} %{INT:response_size:int} %{INT:request_size:int} %{INT:duration_ms:int}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment