# Filebeat multiline - entire log file published as 1 long event

**URL:** <https://discuss.elastic.co/t/filebeat-multiline-entire-log-file-published-as-1-long-event/96716>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 11, 2017, 7:29am UTC](https://discuss.elastic.co/t/filebeat-multiline-entire-log-file-published-as-1-long-event/96716 "2017-08-11T07:29:37Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Roy](https://avatars.discourse-cdn.com/v4/letter/r/4da419/32.png) [@Roy](https://discuss.elastic.co/u/Roy)\
**Post date:** [August 11, 2017, 7:29am UTC](https://discuss.elastic.co/t/filebeat-multiline-entire-log-file-published-as-1-long-event/96716/1 "2017-08-11T07:29:38Z")

</div>

Hi All,

I'm having an issue with filebeat multiline events.  
All log file is being published as 1 long message.

My log lines looks like:  
"GS category US severity..."

The GS is group seperator in unicode, and filebeat reads ir as "\u001d" and logstash receives it as "\u001D"

## Config:

pattern: '^\u001|\u001D'  
negate: true  
match: after

If i'm changing the log to start lines with different seperator, for example "--".

And configuration:  
pattern:'^--'  
negate: true  
match: after

Works perfect..

Can it be a filebeat bug that it can't recognize the GS seperator correctly, or maybe my pattern is incorrect?

Thanks,  
Roy.

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [August 11, 2017, 3:21pm UTC](https://discuss.elastic.co/t/filebeat-multiline-entire-log-file-published-as-1-long-event/96716/2 "2017-08-11T15:21:00Z")

</div>

hm.... I'm not sure `\u` will be correctly interpreted as unicode by the regex parser. Btw, is this correct: `'^\u001|\u001D’` ? Shouldn't it say `^\u001d`. As `\u` meens, interpret these number as unicode, there shouldn't be a difference between `\u001d` and `\u001D`. It's the json encoder sending `\u001D` I guess.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 8, 2017, 3:21pm UTC](https://discuss.elastic.co/t/filebeat-multiline-entire-log-file-published-as-1-long-event/96716/3 "2017-09-08T15:21:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
