# Filebeat dissect line break

**URL:** <https://discuss.elastic.co/t/filebeat-dissect-line-break/272274>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 6, 2021, 10:18am UTC](https://discuss.elastic.co/t/filebeat-dissect-line-break/272274 "2021-05-06T10:18:27Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![mostpha456](https://avatars.discourse-cdn.com/v4/letter/m/7feea3/32.png) [@mostpha456](https://discuss.elastic.co/u/mostpha456)\
**Post date:** [May 6, 2021, 10:18am UTC](https://discuss.elastic.co/t/filebeat-dissect-line-break/272274/1 "2021-05-06T10:18:27Z")

</div>

Hello,  
i am using dissect processor to parse a multiline log.  
i got the error dissect\_parsing\_error, i think it s because of the \n.  
Do you have any idea where i can find any exemple of filebeat dissect for multiline.

Thank you.

---

<div class="post-metadata">

**Author:** ![ChrsMark](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrsmark/32/55858_2.png) [@ChrsMark](https://discuss.elastic.co/u/ChrsMark)\
**Post date:** [May 6, 2021, 10:19am UTC](https://discuss.elastic.co/t/filebeat-dissect-line-break/272274/2 "2021-05-06T10:19:31Z")

</div>

Hi!

One starting point could be the docs: [Dissect strings | Filebeat Reference [7.12] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/dissect.html)

---

<div class="post-metadata">

**Author:** ![mostpha456](https://avatars.discourse-cdn.com/v4/letter/m/7feea3/32.png) [@mostpha456](https://discuss.elastic.co/u/mostpha456)\
**Post date:** [May 6, 2021, 10:40am UTC](https://discuss.elastic.co/t/filebeat-dissect-line-break/272274/3 "2021-05-06T10:40:52Z")

</div>

Hi, thanks for your answer.  
I looked into the doc but i didnt find an exemple how to deal with the line break !

---

<div class="post-metadata">

**Author:** ![ChrsMark](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrsmark/32/55858_2.png) [@ChrsMark](https://discuss.elastic.co/u/ChrsMark)\
**Post date:** [May 6, 2021, 12:09pm UTC](https://discuss.elastic.co/t/filebeat-dissect-line-break/272274/4 "2021-05-06T12:09:47Z")

</div>

All right, since you have multiline logs do you also use [`multiline `](https://www.elastic.co/guide/en/beats/filebeat/current/multiline-examples.html) options so as to congest the lines into one first?

I think that first you will need to handle the multiline lines and then apply the processor on top of it. Sth like this -\> [beats/log.yml at 83f248e3eff044d7785efca79de138d70ee81b4c · elastic/beats · GitHub](https://github.com/elastic/beats/blob/83f248e3eff044d7785efca79de138d70ee81b4c/x-pack/filebeat/module/activemq/log/config/log.yml#L7)

---

<div class="post-metadata">

**Author:** ![mostpha456](https://avatars.discourse-cdn.com/v4/letter/m/7feea3/32.png) [@mostpha456](https://discuss.elastic.co/u/mostpha456)\
**Post date:** [May 6, 2021, 12:26pm UTC](https://discuss.elastic.co/t/filebeat-dissect-line-break/272274/5 "2021-05-06T12:26:23Z")

</div>

Yes , i already configured the multiline, i have the field message in this format  
"id : x  
time : x  
user : x"  
tried to match it with :

- dissect:  
tokenizer: '"id : %{id}\ntime : %{time}\nuser : %{user}"'  
field: "message"  
target\_prefix: ""  
but i am having dissect\_parsing\_error ☹

---

<div class="post-metadata">

**Author:** ![ChrsMark](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrsmark/32/55858_2.png) [@ChrsMark](https://discuss.elastic.co/u/ChrsMark)\
**Post date:** [May 6, 2021, 1:10pm UTC](https://discuss.elastic.co/t/filebeat-dissect-line-break/272274/6 "2021-05-06T13:10:24Z")

</div>

I see...I'm not sure if tokenizer can work with this new\_line thing included. How about using [Script Processor | Filebeat Reference [7.12] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/processor-script.html) so as to have more flexibility to handle the message?

---

<div class="post-metadata">

**Author:** ![mostpha456](https://avatars.discourse-cdn.com/v4/letter/m/7feea3/32.png) [@mostpha456](https://discuss.elastic.co/u/mostpha456)\
**Post date:** [May 6, 2021, 2:06pm UTC](https://discuss.elastic.co/t/filebeat-dissect-line-break/272274/7 "2021-05-06T14:06:11Z")

</div>

Thank you for your answer, i fixed the issue using tokenizer,  
juste deleted the single quote  
tokenizer: "id : %{id}\ntime : %{time}\nuser : %{user}"

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 3, 2021, 4:07pm UTC](https://discuss.elastic.co/t/filebeat-dissect-line-break/272274/8 "2021-06-03T16:07:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
