# Filebeat 1.1.0 exclude lines with only CRLF or LF

**URL:** <https://discuss.elastic.co/t/filebeat-1-1-0-exclude-lines-with-only-crlf-or-lf/41587>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [February 12, 2016, 9:28am UTC](https://discuss.elastic.co/t/filebeat-1-1-0-exclude-lines-with-only-crlf-or-lf/41587 "2016-02-12T09:28:27Z")\
**Posts on this page:** 17\
**Page:** 1

<div class="post-metadata">

**Author:** ![Steiniche](https://avatars.discourse-cdn.com/v4/letter/s/96bed5/32.png) [@Steiniche](https://discuss.elastic.co/u/Steiniche)\
**Post date:** [February 12, 2016, 9:28am UTC](https://discuss.elastic.co/t/filebeat-1-1-0-exclude-lines-with-only-crlf-or-lf/41587/1 "2016-02-12T09:28:27Z")

</div>

Hello,

I have been trying to exclude lines which ONLY contains CRLF or LF i.e. empty lines.  
However, I have not found a solution yet

I have tried with exclude\_lines: ["^\r?\n$"]  
And all the variations I can think of, but I am out of luck!

Sample for testing:  
Caused by: org.error.something.something  
at at.somewhere  
at no.nowhere  
at com.google  
at org.apache  
... 156 more

Remember the last line which should contain either CRLF or LF (depending on the OS)

The filebeat 1.1.0 service is running on Windows Server 2012 R2.

Thank you in advance and thank you for an awesome product stack 🙂

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [February 12, 2016, 11:43am UTC](https://discuss.elastic.co/t/filebeat-1-1-0-exclude-lines-with-only-crlf-or-lf/41587/2 "2016-02-12T11:43:25Z")

</div>

Isn't that identical to excluding empty lines? Means ["^$"] could work (didn't test)?

---

<div class="post-metadata">

**Author:** ![Steiniche](https://avatars.discourse-cdn.com/v4/letter/s/96bed5/32.png) [@Steiniche](https://discuss.elastic.co/u/Steiniche)\
**Post date:** [February 12, 2016, 2:14pm UTC](https://discuss.elastic.co/t/filebeat-1-1-0-exclude-lines-with-only-crlf-or-lf/41587/3 "2016-02-12T14:14:45Z")

</div>

I have just tested your suggestion and I'm afraid it doesn't seem to work.

---

<div class="post-metadata">

**Author:** ![Steiniche](https://avatars.discourse-cdn.com/v4/letter/s/96bed5/32.png) [@Steiniche](https://discuss.elastic.co/u/Steiniche)\
**Post date:** [February 23, 2016, 9:06am UTC](https://discuss.elastic.co/t/filebeat-1-1-0-exclude-lines-with-only-crlf-or-lf/41587/4 "2016-02-23T09:06:15Z")

</div>

I still haven't found a solution to this problem.  
Anyone have any ideas?

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [February 23, 2016, 5:28pm UTC](https://discuss.elastic.co/t/filebeat-1-1-0-exclude-lines-with-only-crlf-or-lf/41587/5 "2016-02-23T17:28:54Z")

</div>

Didn't have time yet to look into this. @steffens Do you have an idea?

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [February 24, 2016, 6:44pm UTC](https://discuss.elastic.co/t/filebeat-1-1-0-exclude-lines-with-only-crlf-or-lf/41587/6 "2016-02-24T18:44:02Z")

</div>

1. in yaml use single quotes, not double quotes for your patterns

2. try pattern `'^[[:space:]]*$'` in case line has unspecified number of whitespace characters. This pattern should match all empty lines and all lines with any number of whitespace characters as in `[\t\n\v\f\r]`

---

<div class="post-metadata">

**Author:** ![mruthyu](https://avatars.discourse-cdn.com/v4/letter/m/bb73d2/32.png) [@mruthyu](https://discuss.elastic.co/u/mruthyu)\
**Post date:** [May 8, 2017, 10:20am UTC](https://discuss.elastic.co/t/filebeat-1-1-0-exclude-lines-with-only-crlf-or-lf/41587/7 "2017-05-08T10:20:08Z")

</div>

I tried exclude\_lines: '^[[:space:]]\*$' in 5.3 filebeat config file, still it is not ignoring the empty lines.

---

<div class="post-metadata">

**Author:** ![mruthyu](https://avatars.discourse-cdn.com/v4/letter/m/bb73d2/32.png) [@mruthyu](https://discuss.elastic.co/u/mruthyu)\
**Post date:** [May 8, 2017, 11:12am UTC](https://discuss.elastic.co/t/filebeat-1-1-0-exclude-lines-with-only-crlf-or-lf/41587/8 "2017-05-08T11:12:52Z")

</div>

There is an empty line within an event, due to which multiline pattern is not considering the lines after the empty line. Subsequent lines after the empty line are considered as separate/different events. Any thoughts to consider this empty line also part of the multiline event.

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [May 9, 2017, 1:08pm UTC](https://discuss.elastic.co/t/filebeat-1-1-0-exclude-lines-with-only-crlf-or-lf/41587/9 "2017-05-09T13:08:53Z")

</div>

Instead of prose, do you have an actual example plus configuration you're using?

The `exclude_lines` filter is applied after multiline. Is multiline spanning the newlines?

---

<div class="post-metadata">

**Author:** ![mruthyu](https://avatars.discourse-cdn.com/v4/letter/m/bb73d2/32.png) [@mruthyu](https://discuss.elastic.co/u/mruthyu)\
**Post date:** [May 10, 2017, 1:35pm UTC](https://discuss.elastic.co/t/filebeat-1-1-0-exclude-lines-with-only-crlf-or-lf/41587/10 "2017-05-10T13:35:57Z")

</div>

Here is the sample log file snippet. You can see a BLANKLINE after line.separator = . So file.encoding = UTF-8 is considered as new event, instead of appending to the event it belongs to.

```auto
2017-04-07 01:44:27,684 INFO [org.jboss.as] (MSC service thread 1-1) WFLYSRV0049: JBoss EAP 7.0.0.GA (WildFly Core 2.1.2.Final-redhat-1) starting
2017-04-07 01:44:27,685 DEBUG [org.jboss.as.config] (MSC service thread 1-1) Configured system properties:
                [Standalone] = 
                awt.toolkit = sun.awt.X11.XToolkit
                line.separator = 
                [BLANK/EMPTY LINE]
                file.encoding = UTF-8

```

Here is the filebeat configuration.

```auto
 exclude_lines: '^[[:space:]]*$'
 multiline.pattern: '^[[:space:]]+|^Caused by:'
multiline.negate: false
multiline.match: after

```

Let me know if any further information is required. Thanks for looking into this post.

---

<div class="post-metadata">

**Author:** ![mruthyu](https://avatars.discourse-cdn.com/v4/letter/m/bb73d2/32.png) [@mruthyu](https://discuss.elastic.co/u/mruthyu)\
**Post date:** [May 10, 2017, 1:36pm UTC](https://discuss.elastic.co/t/filebeat-1-1-0-exclude-lines-with-only-crlf-or-lf/41587/11 "2017-05-10T13:36:57Z")

</div>

I am using 5.3 version of filebeat.

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [May 11, 2017, 10:16am UTC](https://discuss.elastic.co/t/filebeat-1-1-0-exclude-lines-with-only-crlf-or-lf/41587/12 "2017-05-11T10:16:33Z")

</div>

I did try to format you post, but not sure formatting is correct. Please properly format logs using the `</>` button.

why you want `file.encoding` to be another event? This looks like some kind of structured log you can parse in Logstash/Elasticsearch Ingest Node. Other logs might include more fields...

Instead of matching on `space`, you might consider matching on timestamp/blank line and set `multiline.negate: true`.

---

<div class="post-metadata">

**Author:** ![mruthyu](https://avatars.discourse-cdn.com/v4/letter/m/bb73d2/32.png) [@mruthyu](https://discuss.elastic.co/u/mruthyu)\
**Post date:** [May 15, 2017, 1:42pm UTC](https://discuss.elastic.co/t/filebeat-1-1-0-exclude-lines-with-only-crlf-or-lf/41587/13 "2017-05-15T13:42:44Z")

</div>

file.encoding need not be another event. But here it is being considered by file beat as another event just because of the presence of BLANK/EMPTY line just before that.

I tried matching the **timestamp** line and set **multiline.negate: true**. Now I see all events are being appended and finally seeing only one document.

---

<div class="post-metadata">

**Author:** ![mruthyu](https://avatars.discourse-cdn.com/v4/letter/m/bb73d2/32.png) [@mruthyu](https://discuss.elastic.co/u/mruthyu)\
**Post date:** [May 15, 2017, 2:40pm UTC](https://discuss.elastic.co/t/filebeat-1-1-0-exclude-lines-with-only-crlf-or-lf/41587/14 "2017-05-15T14:40:06Z")

</div>

Have used multiline.pattern: '^%{TIMESTAMP\_ISO8601}' and tried with multiline.pattern: '^%{ISO8601}' also.

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [May 15, 2017, 3:40pm UTC](https://discuss.elastic.co/t/filebeat-1-1-0-exclude-lines-with-only-crlf-or-lf/41587/15 "2017-05-15T15:40:08Z")

</div>

given your recent post I guess it's not working yet?

with beats you have to use plain old regexes. e.g. `'^\d{4}-\d{2}-\d{2}` to match a log line starting with a date.

---

<div class="post-metadata">

**Author:** ![mruthyu](https://avatars.discourse-cdn.com/v4/letter/m/bb73d2/32.png) [@mruthyu](https://discuss.elastic.co/u/mruthyu)\
**Post date:** [May 15, 2017, 5:13pm UTC](https://discuss.elastic.co/t/filebeat-1-1-0-exclude-lines-with-only-crlf-or-lf/41587/16 "2017-05-15T17:13:56Z")

</div>

Thank you so much. It did work finally. 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 9:49pm UTC](https://discuss.elastic.co/t/filebeat-1-1-0-exclude-lines-with-only-crlf-or-lf/41587/17 "2017-07-05T21:49:31Z")

</div>


