# Beats Multiline Pattern Error

**URL:** <https://discuss.elastic.co/t/beats-multiline-pattern-error/244458>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 10, 2020, 8:12pm UTC](https://discuss.elastic.co/t/beats-multiline-pattern-error/244458 "2020-08-10T20:12:42Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![ben\_men](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ben_men/32/72569_2.png) [@ben\_men](https://discuss.elastic.co/u/ben_men)\
**Post date:** [August 10, 2020, 8:12pm UTC](https://discuss.elastic.co/t/beats-multiline-pattern-error/244458/1 "2020-08-10T20:12:42Z")

</div>

I am trying to ingest multiline log event with filebeat and using Multiline Pattern but it is not working out as expected. Here is one of the multiline event I have:

```auto
03 Aug 2020 02:39:53,456 DEBUG [sometext] [sometext] ResourceStatusReader:220 - Persisted Resource Event:

EventKOK:
   id = ResourceStatus-kk0000_opiii-2020-08-03T02-39-52Z
   description = Resource Update Event
   type = Comment
   start = Aug 3, 2020 2:39:52 AM [965270392 0 [2020/08/03 02:39:52.000]]
   stop = Aug 3, 2020 2:39:52 AM [965270392 0 [2020/08/03 02:39:52.000]]
   resource names = [kk0000_opiii]
   params = 
Name: Status	Value: OK

```

and the regex I have for the pattern:

```auto
^(?:\d{2}\s[\w]{3}\s\d{4}\s(\d{2}:?){3},\d{3})\s+[A-Z]{4,7}\s+\[.+\]\s+\[.+\]\s+.+\n+^EventKOK:

```

This does not give me one event. But makes it into two separate events. The first one before the return line:

```auto
03 Aug 2020 02:39:53,456 DEBUG [sometext] [sometext] ResourceStatusReader:220 - Persisted Resource Event: 

```

and the other one:

```auto
EventKOK:
   id = ResourceStatus-kk0000_opiii-2020-08-03T02-39-52Z
   description = Resource Update Event
   type = Comment
   start = Aug 3, 2020 2:39:52 AM [965270392 0 [2020/08/03 02:39:52.000]]
   stop = Aug 3, 2020 2:39:52 AM [965270392 0 [2020/08/03 02:39:52.000]]
   resource names = [kk0000_opiii]
   params = 
Name: Status	Value: OK

```

Thank you for your help.

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [August 10, 2020, 8:51pm UTC](https://discuss.elastic.co/t/beats-multiline-pattern-error/244458/2 "2020-08-10T20:51:38Z")

</div>

It seems you would like to partition your events based on the timestamp at the start of the line, right? If so, how about removing this part from the end of your multiline regex: `\n+^EventKOK:`?

Shaunak

---

<div class="post-metadata">

**Author:** ![ben\_men](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ben_men/32/72569_2.png) [@ben\_men](https://discuss.elastic.co/u/ben_men)\
**Post date:** [August 10, 2020, 9:13pm UTC](https://discuss.elastic.co/t/beats-multiline-pattern-error/244458/3 "2020-08-10T21:13:18Z")

</div>

Thank you Shaunak. I tried excluding and including`\n+^EventKOK:`On both cases, filebeat consider it as two different events and raised parsing error for the part starting `EventKOK: id = ResourceStatus-kk0000_opiii-2020-08-03T02-39-52Z description = Resource Update Event type = Comment start = Aug 3, 2020 2:39:52 AM [965270392 0 [2020/08/03 02:39:52.000]] stop = Aug 3, 2020 2:39:52 AM [965270392 0 [2020/08/03 02:39:52.000]] resource names = [kk0000_opiii] params = Name: Status	Value: OK` The whole event, starting with timestamp `03 Aug 2020 02:39:53,456` to the last line, .`Name: Status	Value: OK` should be in one event.

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [August 10, 2020, 11:11pm UTC](https://discuss.elastic.co/t/beats-multiline-pattern-error/244458/4 "2020-08-10T23:11:10Z")

</div>

I just tested your sample log input with the following Filebeat multiline configuration and it seemed to work as expected:

```auto
  multiline:
    pattern: '^\d{2}\s\w{3}\s\d{4}'
    negate: true
    match: after

```

Could you use the above regex?

Shaunak

---

<div class="post-metadata">

**Author:** ![ben\_men](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ben_men/32/72569_2.png) [@ben\_men](https://discuss.elastic.co/u/ben_men)\
**Post date:** [August 11, 2020, 1:59am UTC](https://discuss.elastic.co/t/beats-multiline-pattern-error/244458/5 "2020-08-11T01:59:05Z")

</div>

I see the problem. I have many other multiline patterns which work fine with,

```auto
    negate: false
    match: before

```

When I changed the configuration, it worked now.  
Thank you.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 8, 2020, 3:59am UTC](https://discuss.elastic.co/t/beats-multiline-pattern-error/244458/6 "2020-09-08T03:59:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
