# Elastic Cloud - Data onboarding - line break issue

**URL:** <https://discuss.elastic.co/t/elastic-cloud-data-onboarding-line-break-issue/337507>\
**Category:** Elastic Cloud Enterprise (ECE)\
**Created:** [July 4, 2023, 4:50am UTC](https://discuss.elastic.co/t/elastic-cloud-data-onboarding-line-break-issue/337507 "2023-07-04T04:50:37Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![inventsekar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/inventsekar/32/122976_2.png) [@inventsekar](https://discuss.elastic.co/u/inventsekar)\
**Post date:** [July 4, 2023, 4:50am UTC](https://discuss.elastic.co/t/elastic-cloud-data-onboarding-line-break-issue/337507/1 "2023-07-04T04:50:37Z")

</div>

Hi All.. A complete newbie to ELK.. booked a 2 weeks Elastic cloud and onboarded some sample logs. got stuck with the line break issue.  
(checked the logs and searched on youtube, but no luck)  
i mean.. the sample log is very simple.. it got some 10 lines(no timestamps actually).. each two lines should be one event.  
so, i entered new lines(empty lines) after every two lines of logs.  
now.. when i uploaded this log, i got errors.. i edited the settings on that page(unchecked the timestamp, etc).. to update each two lines as a single event.. i see no options. please suggest, thanks.

---

<div class="post-metadata">

**Author:** ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Post date:** [July 5, 2023, 9:51am UTC](https://discuss.elastic.co/t/elastic-cloud-data-onboarding-line-break-issue/337507/2 "2023-07-05T09:51:58Z")

</div>

Hi @inventsekar,

Welcome to the community! How are you uploading your data into Elasticsearch? Can you share the error you are seeing when trying to ingest the log?

---

<div class="post-metadata">

**Author:** ![inventsekar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/inventsekar/32/122976_2.png) [@inventsekar](https://discuss.elastic.co/u/inventsekar)\
**Post date:** [July 5, 2023, 6:31pm UTC](https://discuss.elastic.co/t/elastic-cloud-data-onboarding-line-break-issue/337507/3 "2023-07-05T18:31:14Z")

</div>

Thanks Carly..  
Actually I am using ELK cloud.. and I just want to upload one simple log file, only once.. (need not monitor the file or anything)..so I am not using any filebeat, etc..

on the elk cloud, data upload option I used.. it worked fine.. but the line breaking gives me difficult time.

Thanks  
Sekar

---

<div class="post-metadata">

**Author:** ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Post date:** [July 6, 2023, 10:58am UTC](https://discuss.elastic.co/t/elastic-cloud-data-onboarding-line-break-issue/337507/4 "2023-07-06T10:58:32Z")

</div>

So to confirm you're not receiving an import error, but are struggling with line breaks in your logs? Can you give an example of the input you have and the result you are trying to achieve?

---

<div class="post-metadata">

**Author:** ![inventsekar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/inventsekar/32/122976_2.png) [@inventsekar](https://discuss.elastic.co/u/inventsekar)\
**Post date:** [July 6, 2023, 11:18am UTC](https://discuss.elastic.co/t/elastic-cloud-data-onboarding-line-break-issue/337507/5 "2023-07-06T11:18:53Z")

</div>

Yep..import initially given some error..  
I unchecked the timestamp (as the logs got no timestamp)  
And I selected that the file as semi structured and delimited by space. then it got imported fine.

But the line break is what the important thing.  
The sample log is very simple... Let's assume I got a notepad file with 100 lines of structured data(a csv file we can say)  
I just want to do line breaking at every two lines.

I did this project using Splunk tool and now I would like to achieve the same thru ELK.  
(I am unable to add a direct YouTube link.. so the link is https // youtu.be / htm6l\_PzWhw )

Pls check this video of just 4 mins.  
Much appreciating your response.

Thanks.  
Sekar

---

<div class="post-metadata">

**Author:** ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Post date:** [July 6, 2023, 11:38am UTC](https://discuss.elastic.co/t/elastic-cloud-data-onboarding-line-break-issue/337507/6 "2023-07-06T11:38:23Z")

</div>

Thanks for sharing the video @inventsekar. Am I right in assuming being able to handle the line breaks is a requirement for you rather than manipulating the file so each event is on a distinct line.

For doing a similar approach to the pattern matching you have in your Splunk video I would recommend looking at pre-processing your data first. One way you could do this is by using [Logstash](https://www.elastic.co/guide/en/logstash/current/getting-started-with-logstash.html) and the [multi-line codec plugin](https://www.elastic.co/guide/en/logstash/current/plugins-codecs-multiline.html) with your regex pattern to ingest the data in the way you want.

Hope that helps! Looking forward to seeing the next video. 😀

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 20, 2023, 11:39am UTC](https://discuss.elastic.co/t/elastic-cloud-data-onboarding-line-break-issue/337507/7 "2023-07-20T11:39:14Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
