# Added new line in my log and cannot get the output correctly in filbeat (need to remove new line)

**URL:** <https://discuss.elastic.co/t/added-new-line-in-my-log-and-cannot-get-the-output-correctly-in-filbeat-need-to-remove-new-line/235123>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [June 1, 2020, 7:52am UTC](https://discuss.elastic.co/t/added-new-line-in-my-log-and-cannot-get-the-output-correctly-in-filbeat-need-to-remove-new-line/235123 "2020-06-01T07:52:43Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![himalc](https://avatars.discourse-cdn.com/v4/letter/h/258eb7/32.png) [@himalc](https://discuss.elastic.co/u/himalc)\
**Post date:** [June 1, 2020, 7:52am UTC](https://discuss.elastic.co/t/added-new-line-in-my-log-and-cannot-get-the-output-correctly-in-filbeat-need-to-remove-new-line/235123/1 "2020-06-01T07:52:43Z")

</div>

How to remove newline using multiline config in filebeat

Log file:

2020-06-01T07:44:31.300103 H 80 DHandler.cpp:953 stdlog sql\_execute 11201 9 handcrafted admin 431-856b {"query","client","execution\_time","total\_time"} {"SELECT user.id AS user\_meta\_id, user\_meta.security\_risk\_score AS user\_meta\_security\_risk\_score  
**FROM** user\_meta  
**WHERE** 2 = ANY user\_meta.department\_ids ORDER BY user\_meta.security\_risk\_score DESC  
**LIMIT** 10","http:10.10.10.1","8","9"}

Expect:  
Every FROM, WHERE and LIMIT has a new line before this string. it should come single line sql

---

<div class="post-metadata">

**Author:** ![himalc](https://avatars.discourse-cdn.com/v4/letter/h/258eb7/32.png) [@himalc](https://discuss.elastic.co/u/himalc)\
**Post date:** [June 1, 2020, 4:06pm UTC](https://discuss.elastic.co/t/added-new-line-in-my-log-and-cannot-get-the-output-correctly-in-filbeat-need-to-remove-new-line/235123/2 "2020-06-01T16:06:38Z")

</div>

This is created to multiple lines but need to access like single line in filebeat.yml  
Any help?

2020-06-01T15:57:48.499723 H 15 Handler.cpp:93 stdlog sql\_execute 34697 9 handcraft user 748-Nue0 {"query\_str","client","execution\_time","total\_time"} {"SELECT user\_meta.id AS user \_meta\_id, user\_meta.security\_risk\_score AS user\_meta\_security\_risk\_score  
FROM user\_meta  
WHERE 0 = 1 ORDER BY user\_meta.security\_risk\_score DESC  
LIMIT 10","http:192.168.1.213","9","9"}

---

<div class="post-metadata">

**Author:** ![Andre\_Letterer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andre_letterer/32/42248_2.png) [@Andre\_Letterer](https://discuss.elastic.co/u/Andre_Letterer)\
**Post date:** [June 1, 2020, 6:02pm UTC](https://discuss.elastic.co/t/added-new-line-in-my-log-and-cannot-get-the-output-correctly-in-filbeat-need-to-remove-new-line/235123/3 "2020-06-01T18:02:53Z")

</div>

I just would use the Multiline config for the timestamp example here:  
[https://www.elastic.co/guide/en/beats/filebeat/current/multiline-examples.html#\_timestamps](https://www.elastic.co/guide/en/beats/filebeat/current/multiline-examples.html#_timestamps)

So in your case it would be to place the multiline config into you input section:

```auto
multiline.pattern: '^[0-9]{4}-[0-9]{2}-[0-9]{2}'
multiline.negate: true
multiline.match: after

```

---

<div class="post-metadata">

**Author:** ![himalc](https://avatars.discourse-cdn.com/v4/letter/h/258eb7/32.png) [@himalc](https://discuss.elastic.co/u/himalc)\
**Post date:** [June 2, 2020, 3:59am UTC](https://discuss.elastic.co/t/added-new-line-in-my-log-and-cannot-get-the-output-correctly-in-filbeat-need-to-remove-new-line/235123/4 "2020-06-02T03:59:36Z")

</div>

Hi Andre,  
Thanks a lot your suggestion. Actually I have used this pattern and some other pattern for my filebeat. Its work for few queries. Not all the queries (long queries with JOIN, select in side the select ). Is there any query string limitation on filebeat?

---

<div class="post-metadata">

**Author:** ![Andre\_Letterer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andre_letterer/32/42248_2.png) [@Andre\_Letterer](https://discuss.elastic.co/u/Andre_Letterer)\
**Post date:** [June 2, 2020, 11:08pm UTC](https://discuss.elastic.co/t/added-new-line-in-my-log-and-cannot-get-the-output-correctly-in-filbeat-need-to-remove-new-line/235123/5 "2020-06-02T23:08:54Z")

</div>

Hm, can you write an example that doesn't work? You can remove confidential information.

---

<div class="post-metadata">

**Author:** ![himalc](https://avatars.discourse-cdn.com/v4/letter/h/258eb7/32.png) [@himalc](https://discuss.elastic.co/u/himalc)\
**Post date:** [June 8, 2020, 2:58pm UTC](https://discuss.elastic.co/t/added-new-line-in-my-log-and-cannot-get-the-output-correctly-in-filbeat-need-to-remove-new-line/235123/6 "2020-06-08T14:58:15Z")

</div>

Hi Andre,

Sorry for the late reply. Actually, your suggestion was good. it was work for me. Thanks a lot.

---

<div class="post-metadata">

**Author:** ![Andre\_Letterer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andre_letterer/32/42248_2.png) [@Andre\_Letterer](https://discuss.elastic.co/u/Andre_Letterer)\
**Post date:** [June 8, 2020, 6:11pm UTC](https://discuss.elastic.co/t/added-new-line-in-my-log-and-cannot-get-the-output-correctly-in-filbeat-need-to-remove-new-line/235123/7 "2020-06-08T18:11:27Z")

</div>

Perfect, that's great to hear.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2020, 6:11pm UTC](https://discuss.elastic.co/t/added-new-line-in-my-log-and-cannot-get-the-output-correctly-in-filbeat-need-to-remove-new-line/235123/8 "2020-07-06T18:11:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
