# Filebeat Inserts \\t in place of tabs

**URL:** <https://discuss.elastic.co/t/filebeat-inserts-t-in-place-of-tabs/49242>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 5, 2016, 1:58am UTC](https://discuss.elastic.co/t/filebeat-inserts-t-in-place-of-tabs/49242 "2016-05-05T01:58:11Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![sghosh](https://avatars.discourse-cdn.com/v4/letter/s/9de053/32.png) [@sghosh](https://discuss.elastic.co/u/sghosh)\
**Post date:** [May 5, 2016, 1:58am UTC](https://discuss.elastic.co/t/filebeat-inserts-t-in-place-of-tabs/49242/1 "2016-05-05T01:58:11Z")

</div>

Hi All,

I am trying to ship logs from servers via filebeat. I faced an issue like this:

Whenever FB forwards log events to remote LS it inserts the literal string \t in place of tab characters. This messes up the logstash grok filters. I have just printed to a file via LS whatever FB gives to it. I noticed the above behavior from this file only. A sample message received by LS would be

"{"message":"2016-05-05 01:44:44,487 INFO [d7d91583-a5f0-4613-ab16-2c9eb4ec69ab] [org.restlet.SpringComponent.LogService] - 2016-05-05\t01:44:44\t192.168.188.101\tsample-api-xY.Sec.re$#@6-FANtasTIC898\t192.168.188.101\t443\tGET\t/api/service\t-\t200\t317\t0\t353\thttps://api.sample.com\tsample-sdk-java/0.1 Linux/2.6.32-573.el6.x86\_64 Java\_HotSpot(TM)\_64-Bit\_Server\_VM/25.72-b15\t-"

As you can see there are a lot of \t characters.

My FB config has the following multiline config:

multiline:  
pattern : "^%{TIMESTAMP\_ISO8601}"  
negate: true  
match: after

encoding: utf-8

Any hints where should i be looking at ?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 8, 2016, 8:18pm UTC](https://discuss.elastic.co/t/filebeat-inserts-t-in-place-of-tabs/49242/2 "2016-05-08T20:18:10Z")

</div>

In JSON, tab characters are represented by \t so Filebeat isn't doing anything wrong. I'd say the problem is with your grok filter.

---

<div class="post-metadata">

**Author:** ![sghosh](https://avatars.discourse-cdn.com/v4/letter/s/9de053/32.png) [@sghosh](https://discuss.elastic.co/u/sghosh)\
**Post date:** [May 8, 2016, 9:48pm UTC](https://discuss.elastic.co/t/filebeat-inserts-t-in-place-of-tabs/49242/3 "2016-05-08T21:48:14Z")

</div>

Thanks.. got it.. Fixed the grok. One more question: If there are too many  
new lines I am getting multiline error. This is okay but the second part of  
the truncated multiline event is not getting dropped. It is being treated  
as a separate event nd causing grokparse failure. Any idea how to deal with  
it?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 9, 2016, 5:55am UTC](https://discuss.elastic.co/t/filebeat-inserts-t-in-place-of-tabs/49242/4 "2016-05-09T05:55:57Z")

</div>

Please give an example of some input lines that aren't correctly joined to a single event.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 9:52pm UTC](https://discuss.elastic.co/t/filebeat-inserts-t-in-place-of-tabs/49242/5 "2017-07-05T21:52:18Z")

</div>


