# Configure FileBeat to combine all logs without multiline pattern

**URL:** <https://discuss.elastic.co/t/configure-filebeat-to-combine-all-logs-without-multiline-pattern/207256>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [November 10, 2019, 10:01pm UTC](https://discuss.elastic.co/t/configure-filebeat-to-combine-all-logs-without-multiline-pattern/207256 "2019-11-10T22:01:47Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![abhisekdg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/abhisekdg/32/20997_2.png) [@abhisekdg](https://discuss.elastic.co/u/abhisekdg)\
**Post date:** [November 10, 2019, 10:01pm UTC](https://discuss.elastic.co/t/configure-filebeat-to-combine-all-logs-without-multiline-pattern/207256/1 "2019-11-10T22:01:48Z")

</div>

I am using Filebeat 6.4.2, Logstash 6.3.1 and want to combine all logs files on the filebeat input path \</var/log/application.log\> . Logs don't have any specific pattern to start with or end with.

```auto
    filebeat.inputs:

    - type: log
      enabled: true
      paths:
        - /var/log/application.log
      fields:
        type: admin
        tags: admin
      fields_under_root: true

      multiline.pattern: '.' 
      multiline.negate: true
      multiline.match: after
      multiline.max_lines: 1000

output.logstash:
  # The Logstash hosts
  hosts: ["xxx.20.x.xxx:5043"]

```

Note : Logs don't have any specific pattern. I want to capture all combined logs in Logstash together in bunch of max lines specified.

I tried with multiple RegEx in the pattern sections, it's not working. Problem is logs does'nt come in any specific pattern.

---

<div class="post-metadata">

**Author:** ![exekias](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/exekias/32/28718_2.png) [@exekias](https://discuss.elastic.co/u/exekias)\
**Post date:** [November 13, 2019, 2:17pm UTC](https://discuss.elastic.co/t/configure-filebeat-to-combine-all-logs-without-multiline-pattern/207256/2 "2019-11-13T14:17:03Z")

</div>

Hi @abhisekdg,

I wonder how big can this file get? A config like this should probably work (didn't test it):

```auto
multiline.pattern: .
multiline.match: after
multiline.negate: false

```

---

<div class="post-metadata">

**Author:** ![abhisekdg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/abhisekdg/32/20997_2.png) [@abhisekdg](https://discuss.elastic.co/u/abhisekdg)\
**Post date:** [November 18, 2019, 6:49am UTC](https://discuss.elastic.co/t/configure-filebeat-to-combine-all-logs-without-multiline-pattern/207256/4 "2019-11-18T06:49:37Z")

</div>

HI @exekias, I checked the multiline pattern configuration.  
It not worked for me. Still all the logs are coming as separate document in logstash.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 16, 2019, 6:49am UTC](https://discuss.elastic.co/t/configure-filebeat-to-combine-all-logs-without-multiline-pattern/207256/5 "2019-12-16T06:49:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
