I am using
logstash 2.2.1 ,
logstash-input beats-2.1.3 and
filebeat 1.1.2 . I have some XML type of log files. I have written beats config. I am facing the following issue
Issue 1: The xml log file multiline events are not getting combined into single event as expected.
Below is my beats yml file configuration.
> filebeat: > prospectors: > - > paths: > - /logs/mylogs/2015*/*.xml > document_type: server_log > registry_file: /myarea/config/mylogs/.filebeat > multiline: pattern: "^<error" > negate: true > match: after > output: > logstash: > hosts: ["localhost:11689"] > console: > pretty: true
My sample XML log will be in below format
<error id="1qas79" host="hhy789"> <snapshot> <variable name="a"> <item string="sss"> </item> </variable> </snapshot> </error>