# Filebeat multiline is ignoring my settings

**URL:** <https://discuss.elastic.co/t/filebeat-multiline-is-ignoring-my-settings/171194>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [March 6, 2019, 8:19pm UTC](https://discuss.elastic.co/t/filebeat-multiline-is-ignoring-my-settings/171194 "2019-03-06T20:19:17Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![eran.yo](https://avatars.discourse-cdn.com/v4/letter/e/cc9497/32.png) [@eran.yo](https://discuss.elastic.co/u/eran.yo)\
**Post date:** [March 6, 2019, 8:19pm UTC](https://discuss.elastic.co/t/filebeat-multiline-is-ignoring-my-settings/171194/1 "2019-03-06T20:19:17Z")

</div>

Hi All,

I'm trying to use the filebeat multiline option to marge logs data that have header and footer.

My system logs have fixed header (#SQ#)and footer (#EOM#).  
for example :

#SQ#|1551902277335100043|2019-03-06 21:57:57.335|INFO|0x00007f4570d1f700:c0s3|127.0.0.1|5000|0|master|qwerty11|3|qwerty11|32|"1"|#EOM#

While the log line fit to one line everything is OK and I gets one entry in Kibana.  
But sometime when the log is long the system divide it to few lines, but the fixed header and footer are starting and ending the log, for example :

#SQ#|1551903090635451463|2019-03-06 22:11:30.634|INFO|0x00007f4570d1f700:c0s3|127.0.0.1|5000|0|master|qwerty11|4|qwerty11|1|"SELECT l\_returnflag,  
l\_linestatus,  
l\_linestatus  
ORDER BY l\_returnflag,  
l\_linestatus  
;"|#EOM#

But in this case in Kibaba ill see for each log line different entry .

I tried to set the multiline option in filebeat.yml as follow :

multiline.pattern: '#SQ#'  
multiline.negate: true  
multiline.match: after  
multiline.flush\_pattern: '#EOM#'

But it doesn't meagre the all the log value between my header and footer values.

My ELK stack flow is : log file --\>Filebeat--\>Elasticelasticsearch--\>Kibana

Can someone please help me and advice what i'm doing wrong?

Thanks,  
Eran.

---

<div class="post-metadata">

**Author:** ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)\
**Post date:** [March 7, 2019, 3:22pm UTC](https://discuss.elastic.co/t/filebeat-multiline-is-ignoring-my-settings/171194/2 "2019-03-07T15:22:12Z")

</div>

Hello @eran.yo,

Can you try with the following options?

```auto
multiline.pattern: '^#SQ#'
multiline.negate: true

```

I don't think you need `flush_pattern` since you have a distinct beginning of event and the last event will be flush by the timeout.

I've used the following [playground](https://play.golang.org/p/g9A8ayn0W68) to test your options.

---

<div class="post-metadata">

**Author:** ![eran.yo](https://avatars.discourse-cdn.com/v4/letter/e/cc9497/32.png) [@eran.yo](https://discuss.elastic.co/u/eran.yo)\
**Post date:** [March 10, 2019, 11:24am UTC](https://discuss.elastic.co/t/filebeat-multiline-is-ignoring-my-settings/171194/3 "2019-03-10T11:24:29Z")

</div>

Hi @pierhugues,

Thanks a lot for your help here.  
This option solved my issue 🙂

Thanks,  
Eran.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 7, 2019, 11:24am UTC](https://discuss.elastic.co/t/filebeat-multiline-is-ignoring-my-settings/171194/4 "2019-04-07T11:24:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
