hi,
I have a multiline configuration like this:
multiline.pattern : '^.{22}*'
multiline.negate: false
multiline.match: after
and filebeat joins the lines if a * is found at column 23
each original line has a \t to separate fields, so it would be nice if filebeat add a \t before joining lines
So, If a line has 10 \t separator, it is a concatenation of two lines; if a line has 15 \t separator; it is a concatenation of three lines and so on.
Is it possible ?
If I understand you correctly, you want to replace * with \t. Filebeat still inserts the \n character. You will have to use logstash or elasticsearch ingest node to do additional processing to replace characters.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.