# Filebeat 5.0 with multiline, split event data to two events

**URL:** <https://discuss.elastic.co/t/filebeat-5-0-with-multiline-split-event-data-to-two-events/60380>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [September 13, 2016, 1:08pm UTC](https://discuss.elastic.co/t/filebeat-5-0-with-multiline-split-event-data-to-two-events/60380 "2016-09-13T13:08:10Z")\
**Posts on this page:** 1\
**Showing post:** 5

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [September 14, 2016, 12:32am UTC](https://discuss.elastic.co/t/filebeat-5-0-with-multiline-split-event-data-to-two-events/60380/5 "2016-09-14T00:32:25Z")

</div>

> [@ori.rubinfeld](#):
>
> If it was a timeout, then I would expect to see many small events for each unrelated line from the stack trace

Good point.

So how about adding a file output so you can inspect the events generated by Filebeat and enabling debug logging. Then next time you get a stack trace event published to ES that is split across two events you can check what the event looked like in the file output and find the logs that correspond to when the stack trace was processed.

---

_[View the full topic](https://discuss.elastic.co/t/filebeat-5-0-with-multiline-split-event-data-to-two-events/60380)._
