# Can i send multiple line log directly to elastic search using file beat?

**URL:** <https://discuss.elastic.co/t/can-i-send-multiple-line-log-directly-to-elastic-search-using-file-beat/162900>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [January 4, 2019, 6:47am UTC](https://discuss.elastic.co/t/can-i-send-multiple-line-log-directly-to-elastic-search-using-file-beat/162900 "2019-01-04T06:47:12Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mayurbiw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mayurbiw/32/45858_2.png) [@Mayurbiw](https://discuss.elastic.co/u/Mayurbiw)\
**Post date:** [January 4, 2019, 6:47am UTC](https://discuss.elastic.co/t/can-i-send-multiple-line-log-directly-to-elastic-search-using-file-beat/162900/1 "2019-01-04T06:47:12Z")

</div>

consider this scenario -

This is log file (Directly taken from example conf files in file beat reference)

Exception in thread "main" java.lang.NullPointerException  
at com.example.myproject.Book.getTitle(Book.java:16)  
at com.example.myproject.Author.getBookTitles(Author.java:25)  
at com.example.myproject.Bootstrap.main(Bootstrap.java:14)

This is the filebeat.yml multiline settings

multiline.pattern: '^[[:space:]]'  
multiline.negate: false  
multiline.match: after

the output is an elastic search.

On analysing elastic search using kibana I found out that each line is stored in a separate document.

Can I store multiple lines in a message field of a document?

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [January 4, 2019, 8:05am UTC](https://discuss.elastic.co/t/can-i-send-multiple-line-log-directly-to-elastic-search-using-file-beat/162900/2 "2019-01-04T08:05:57Z")

</div>

Multiline messages are stored in the same document. The example configuration you have pulled from our website is correct and multiple lines are aggregated into a single document.  
Could you please share your whole configuration formatted using `</>`? There might be a whitespace problem somewhere in your config which causes the problem.

---

<div class="post-metadata">

**Author:** ![Mayurbiw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mayurbiw/32/45858_2.png) [@Mayurbiw](https://discuss.elastic.co/u/Mayurbiw)\
**Post date:** [January 4, 2019, 8:20am UTC](https://discuss.elastic.co/t/can-i-send-multiple-line-log-directly-to-elastic-search-using-file-beat/162900/3 "2019-01-04T08:20:48Z")

</div>

filebeat.yml

```
filebeat.inputs:

- type: log

    - /home/oracle/example3.aud

multiline.pattern: '^[[:space:]]'
multiline.negate: false
multiline.match: after

output.elasticsearch:
  
  hosts: ["IPadress:9200"]

  index: "file_beat_example3"

setup.template.name: "file_beat_example3"
setup.template.pattern: "file_beat*"

```

content in example3 file

```
Exception in thread "main" java.lang.NullPointerException
        at com.example.myproject.Book.getTitle(Book.java:16)
        at com.example.myproject.Author.getBookTitles(Author.java:25)
        at com.example.myproject.Bootstrap.main(Bootstrap.java:14)

```

Kibana output

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/7/d784cdf0c3797c16f140aba75c3d0e7fd794b0d4.png)

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [January 4, 2019, 9:00am UTC](https://discuss.elastic.co/t/can-i-send-multiple-line-log-directly-to-elastic-search-using-file-beat/162900/4 "2019-01-04T09:00:44Z")

</div>

Your input configuration seems incorrect. The input needs to be enabled. Also, `multiline` settings need to be at the level of the input.

The correct format:

```auto
filebeat.inputs:
- type: log
  enabled: true
  paths:
    - /home/oracle/example3.aud
  multiline.pattern: '^[[:space:]]'
  multiline.negate: false
  multiline.match: after

```

---

<div class="post-metadata">

**Author:** ![Mayurbiw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mayurbiw/32/45858_2.png) [@Mayurbiw](https://discuss.elastic.co/u/Mayurbiw)\
**Post date:** [January 4, 2019, 9:24am UTC](https://discuss.elastic.co/t/can-i-send-multiple-line-log-directly-to-elastic-search-using-file-beat/162900/5 "2019-01-04T09:24:50Z")

</div>

Thankyou for the help now I am getting mapping error. here is the full filebeat.yml file.  
and previously also enabled was set to true.

```
filebeat.inputs:
- type: log
  enabled: true
  paths:
    - /home/oracle/example4.aud

             multiline.pattern: '^[[:space:]]'
             multiline.negate: false
             multiline.match: after

output.elasticsearch:
  # Array of hosts to connect to.
  hosts: ["IP:9200"]

  index: "file_beat_example4"

setup.template.name: "file_beat_example4"
setup.template.pattern: "file_beat*"

```

Now I am getting the error  
mapping values are not allowed in this context when i am running filebeats

![image](https://us1.discourse-cdn.com/elastic/original/3X/a/3/a3f42d5529b0918658d4a9ea004427484a95e640.png)

error at line number 22 mapping values are not allowed in this context

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [January 4, 2019, 10:03am UTC](https://discuss.elastic.co/t/can-i-send-multiple-line-log-directly-to-elastic-search-using-file-beat/162900/6 "2019-01-04T10:03:10Z")

</div>

Could you copy the exact error message here? Also, is there any error in the logs of Elasticsearch?

---

<div class="post-metadata">

**Author:** ![Mayurbiw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mayurbiw/32/45858_2.png) [@Mayurbiw](https://discuss.elastic.co/u/Mayurbiw)\
**Post date:** [January 4, 2019, 11:21am UTC](https://discuss.elastic.co/t/can-i-send-multiple-line-log-directly-to-elastic-search-using-file-beat/162900/7 "2019-01-04T11:21:35Z")

</div>

Sure  
`Exiting: error loading config file: yaml: line 22: mapping values are not allowed in this context`

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [January 4, 2019, 11:29am UTC](https://discuss.elastic.co/t/can-i-send-multiple-line-log-directly-to-elastic-search-using-file-beat/162900/8 "2019-01-04T11:29:23Z")

</div>

The indentation is still off. The section `multiline` needs to be in the same column as the input. See my configuration snippet. I think your editor is interfering with the indentation of the config. You need to use spaces and do not let your editor mix tabs and spaces.

---

<div class="post-metadata">

**Author:** ![Mayurbiw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mayurbiw/32/45858_2.png) [@Mayurbiw](https://discuss.elastic.co/u/Mayurbiw)\
**Post date:** [January 4, 2019, 11:34am UTC](https://discuss.elastic.co/t/can-i-send-multiple-line-log-directly-to-elastic-search-using-file-beat/162900/9 "2019-01-04T11:34:23Z")

</div>

thank, this solved the problem. I really appreciate your patience. Thank you again.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 1, 2019, 11:34am UTC](https://discuss.elastic.co/t/can-i-send-multiple-line-log-directly-to-elastic-search-using-file-beat/162900/10 "2019-02-01T11:34:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
