# File beat multiline is not working for XML type of files

**URL:** <https://discuss.elastic.co/t/file-beat-multiline-is-not-working-for-xml-type-of-files/45067>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [March 22, 2016, 6:34am UTC](https://discuss.elastic.co/t/file-beat-multiline-is-not-working-for-xml-type-of-files/45067 "2016-03-22T06:34:17Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![rajkamalkool6](https://avatars.discourse-cdn.com/v4/letter/r/e9c0ed/32.png) [@rajkamalkool6](https://discuss.elastic.co/u/rajkamalkool6)\
**Post date:** [March 22, 2016, 6:34am UTC](https://discuss.elastic.co/t/file-beat-multiline-is-not-working-for-xml-type-of-files/45067/1 "2016-03-22T06:34:17Z")

</div>

Hi,

I am using `logstash 2.2.1` ,`logstash-input beats-2.1.3` and `filebeat 1.1.2` . I have some XML type of log files. I have written beats config. I am facing the following issue

**Issue 1** : The xml log file multiline events are not getting combined into single event as expected.

Below is my beats yml file configuration.

```
> filebeat:
> prospectors:
> -
> paths:
> - /logs/mylogs/2015*/*.xml
> document_type: server_log
> registry_file: /myarea/config/mylogs/.filebeat      
> multiline:
    pattern: "^<error"
> negate: true
> match: after
> output: 
> logstash:     
> hosts: ["localhost:11689"]
> console:
> pretty: true

```

My sample XML log will be in below format

```
<error id="1qas79" host="hhy789">
<snapshot>
<variable name="a">
  <item string="sss"> </item>
</variable>
</snapshot>
</error>
```

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [March 22, 2016, 11:30am UTC](https://discuss.elastic.co/t/file-beat-multiline-is-not-working-for-xml-type-of-files/45067/2 "2016-03-22T11:30:51Z")

</div>

For regexes better use single quotes: `pattern: '^<error'`.

See [this regex sample code](http://play.golang.org/p/HMxw_CWZW6) and press run. Every line beginning with `false` should indicate a new multiline-event

Content is 2 xml events as mentioned in variable `content`, and regular expression in `pattern`. Try by replacing `content` with a few events/lines from your original logs and see if pattern works ok.

Is there a chance of having whitespace before `<error>`?

---

<div class="post-metadata">

**Author:** ![rajkamalkool6](https://avatars.discourse-cdn.com/v4/letter/r/e9c0ed/32.png) [@rajkamalkool6](https://discuss.elastic.co/u/rajkamalkool6)\
**Post date:** [March 22, 2016, 11:46am UTC](https://discuss.elastic.co/t/file-beat-multiline-is-not-working-for-xml-type-of-files/45067/3 "2016-03-22T11:46:53Z")

</div>

Thanks for your guidance. Let me try your suggestion and let you know the result.

There is no whitespace before my tag `<error>`

---

<div class="post-metadata">

**Author:** ![rajkamalkool6](https://avatars.discourse-cdn.com/v4/letter/r/e9c0ed/32.png) [@rajkamalkool6](https://discuss.elastic.co/u/rajkamalkool6)\
**Post date:** [March 25, 2016, 5:59am UTC](https://discuss.elastic.co/t/file-beat-multiline-is-not-working-for-xml-type-of-files/45067/4 "2016-03-25T05:59:38Z")

</div>

Hi Steffen, I have tried the `pattern: '^<error'.` and I also include one more proerty in my beats YML file. `input_type: xml`. After this my issue got resolved.

Thank you steffen

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [March 27, 2016, 7:32pm UTC](https://discuss.elastic.co/t/file-beat-multiline-is-not-working-for-xml-type-of-files/45067/5 "2016-03-27T19:32:11Z")

</div>

@rajkamalkool6 `input_type: xml` is not a valid input type. Not sure how that helped?

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [March 29, 2016, 12:05pm UTC](https://discuss.elastic.co/t/file-beat-multiline-is-not-working-for-xml-type-of-files/45067/6 "2016-03-29T12:05:35Z")

</div>

you sure logs are send correctly? There is no `input_type: xml`. Valid values for `input_type` are `log` and `stdin` only.

---

<div class="post-metadata">

**Author:** ![rajkamalkool6](https://avatars.discourse-cdn.com/v4/letter/r/e9c0ed/32.png) [@rajkamalkool6](https://discuss.elastic.co/u/rajkamalkool6)\
**Post date:** [April 1, 2016, 7:11am UTC](https://discuss.elastic.co/t/file-beat-multiline-is-not-working-for-xml-type-of-files/45067/7 "2016-04-01T07:11:31Z")

</div>

No after removing `input_type: xml` its working, by default its taking as log only.

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [April 1, 2016, 11:17am UTC](https://discuss.elastic.co/t/file-beat-multiline-is-not-working-for-xml-type-of-files/45067/8 "2016-04-01T11:17:20Z")

</div>

`input_type: xml` doesn't exists. `input_type` is kind of the 'plugin'-type to use. As `xml` does not exist it will fall back for `log`.

---

<div class="post-metadata">

**Author:** ![rajkamalkool6](https://avatars.discourse-cdn.com/v4/letter/r/e9c0ed/32.png) [@rajkamalkool6](https://discuss.elastic.co/u/rajkamalkool6)\
**Post date:** [April 1, 2016, 11:37am UTC](https://discuss.elastic.co/t/file-beat-multiline-is-not-working-for-xml-type-of-files/45067/9 "2016-04-01T11:37:40Z")

</div>

Yes you are right

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 9:53pm UTC](https://discuss.elastic.co/t/file-beat-multiline-is-not-working-for-xml-type-of-files/45067/10 "2017-07-05T21:53:57Z")

</div>


