# Filebeat multiline directly to elasticsearch

**URL:** <https://discuss.elastic.co/t/filebeat-multiline-directly-to-elasticsearch/172794>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [March 18, 2019, 2:16pm UTC](https://discuss.elastic.co/t/filebeat-multiline-directly-to-elasticsearch/172794 "2019-03-18T14:16:20Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Matus\_Gajdos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matus_gajdos/32/42243_2.png) [@Matus\_Gajdos](https://discuss.elastic.co/u/Matus_Gajdos)\
**Post date:** [March 18, 2019, 2:16pm UTC](https://discuss.elastic.co/t/filebeat-multiline-directly-to-elasticsearch/172794/1 "2019-03-18T14:16:20Z")

</div>

Hello,

I would like to send application logs from filebeat directly to elasticsearch index.

I'm trying send multiline message but in index I see it as single line.

```auto
EmbargoServiceLogger Error: 92 : 3/12/2019 1:46:29 PM##4784##8100##Creation of listner #7 failed. Exception:System.IO.FileNotFoundException: Error reading the Test\To\AllianceManual\Screening\SRC directory.
   at System.IO.FileSystemWatcher.StartRaisingEvents()
   at EmbargoSvc.AMLEmbargoService.StartFileImport()

```

my filebeat.yml multiline configuration is following:

```auto
multiline.pattern: '^[[:space:]]'
multiline.negate: false
multiline.match: after

```

Could somebody help me with this?

Thx

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [March 18, 2019, 9:19pm UTC](https://discuss.elastic.co/t/filebeat-multiline-directly-to-elasticsearch/172794/2 "2019-03-18T21:19:01Z")

</div>

Hi @Matus_Gajdos,

Welcome!

I tried your settings and sample message with my Filebeat and I'm seeing a multiline (`\n`-delimited) message in Kibana Discover:

![19%20PM](https://us1.discourse-cdn.com/elastic/original/3X/1/7/174ae790a283ae4ae298e4df61c2cbe5b4659e2f.jpeg)

What are you seeing in your Kibana Discover? Alternatively, you could just post the complete Elasticsearch document for that log entry over here as well.

---

<div class="post-metadata">

**Author:** ![Matus\_Gajdos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matus_gajdos/32/42243_2.png) [@Matus\_Gajdos](https://discuss.elastic.co/u/Matus_Gajdos)\
**Post date:** [March 19, 2019, 10:06am UTC](https://discuss.elastic.co/t/filebeat-multiline-directly-to-elasticsearch/172794/3 "2019-03-19T10:06:35Z")

</div>

Hello @shaunak

here is what I see in kibana

 ![%24FB4D8878B48DDA7](https://us1.discourse-cdn.com/elastic/original/3X/e/7/e7751db49b6fce41adc23dbd99bed6d34ef0b3ec.jpeg)

Could you send me your filebeat configuration?  
Are you sending data directly to elasticsearch or through logstash?

Thank you.

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [March 20, 2019, 11:54am UTC](https://discuss.elastic.co/t/filebeat-multiline-directly-to-elasticsearch/172794/4 "2019-03-20T11:54:20Z")

</div>

So, first, I tested with the `console` output, just for debugging purposes. For that, my `filebeat.yml` looked like this:

```auto
filebeat.inputs:

- type: stdin
  enabled: true

  multiline.pattern: '^[[:space:]]'
  multiline.negate: false
  multiline.match: after

output.console:
  enabled: true

```

Using that configuration, when I supplied your sample input on STDIN, I got the following output on STDOUT (in the console):

```auto
{"@timestamp":"2019-03-20T11:51:03.693Z","@metadata":{"beat":"filebeat","type":"_doc","version":"8.0.0"},"message":"EmbargoServiceLogger Error: 92 : 3/12/2019 1:46:29 PM##4784##8100##Creation of listner #7 failed. Exception:System.IO.FileNotFoundException: Error reading the Test\\To\\AllianceManual\\Screening\\SRC directory.\n at System.IO.FileSystemWatcher.StartRaisingEvents()\n at EmbargoSvc.AMLEmbargoService.StartFileImport()","input":{"type":"stdin"},"ecs":{"version":"1.0.0"},"host":{"name":"Shaunaks-MBP-2"},"agent":{"version":"8.0.0","type":"filebeat","ephemeral_id":"1bc476cb-af43-440b-8626-61184b65792b","hostname":"Shaunaks-MBP-2","id":"51a8bb52-16b0-4129-a33b-9fba504fe6e8"},"log":{"flags":["multiline"],"offset":0,"file":{"path":""}}}

```

Note the `\n` characters in the `message` field.

Next, I changed the output to `elasticsearch` and provided the same input via STDIN. In that case I got what I posted earlier in the Kibana screenshot.

Are you sending via Logstash? Could you try the `console` output first like I did, just for debugging purposes?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 17, 2019, 11:54am UTC](https://discuss.elastic.co/t/filebeat-multiline-directly-to-elasticsearch/172794/5 "2019-04-17T11:54:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
