# Filebeat Multiline not working-sundar

**URL:** <https://discuss.elastic.co/t/filebeat-multiline-not-working-sundar/173429>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [March 22, 2019, 5:44am UTC](https://discuss.elastic.co/t/filebeat-multiline-not-working-sundar/173429 "2019-03-22T05:44:11Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![sundarm](https://avatars.discourse-cdn.com/v4/letter/s/9de0a6/32.png) [@sundarm](https://discuss.elastic.co/u/sundarm)\
**Post date:** [March 22, 2019, 5:44am UTC](https://discuss.elastic.co/t/filebeat-multiline-not-working-sundar/173429/1 "2019-03-22T05:44:11Z")

</div>

Team,

I am using following filebeat configuration to push magento logs to logstash and from there to kibana. But still its not working as expected . Earlier i used the below logstash configuration without using filebeats and it worked as expected but it eats lots of my server memory .

input {  
file {  
path =\> "/var/www/html/var/log/\*.log"  
path =\> "/var/log/nginx/access.log"  
start\_position =\> "beginning"  
codec =\> multiline {  
pattern =\> "[[\d]{4}"  
negate =\> "true"  
what =\> "previous"  
}  
sincedb\_path =\> "/dev/null"  
}  
}

filter {  
mutate {  
gsub =\> ["message", "\r|\n", ""]  
}  
grok {  
match =\> {  
"message" =\> [  
#"[%{TIMESTAMP\_ISO8601:timestamp}] %{DATA:logger}.%{LOGLEVEL:level}: (?[^{]_) %{GREEDYDATA:context}",  
"[%{TIMESTAMP\_ISO8601:timestamp}] %{DATA:logger}.%{LOGLEVEL:level}: (?[^{]_) (?(.|\r|\n)\*) ",  
"%{GREEDYDATA:logmessage}"  
]  
}  
#match =\> ["message", "[%{TIMESTAMP\_ISO8601:timestamp}] %{DATA:logger}.%{LOGLEVEL:level}: %{GREEDYDATA:context}", "%{GREEDYDATA:context}"]  
}  
json {  
source =\> "context"  
target =\> "jsonparsed"  
}  
}

Now i am trying to push logs via filebeats to logstash My filebeat config and logstash config as below but its not working as expected .

filebeat.inputs:

- type: log  
enabled: true  
paths:
  - /var/www/html/var/log/restapi.log  
fields:
# used in the output section to send each log to its

# proper index instead of the default 'filebeat-\*'
index\_name: qa2magento  
env: qa2magento  
setup.template.enabled: false  
#multiline.pattern: '^[%{TIMESTAMP\_ISO8601}]'  
#multiline.negate: true  
#multiline.match: after  
multiline.pattern: '[%{TIMESTAMP\_ISO8601}]'  
#multiline.pattern: '^[[:space:]]'  
#multiline.pattern: '^['  
multiline.negate: true  
multiline.match: after

output.logstash:  
hosts: ["x.x.x.x:5044"]  
bulk\_max\_size: 1024

# index: "%{[fields.index\_name]:logs}-%{+YYYY.MM.dd}"

logging:  
level: info

logging.to\_syslog: false  
logging.to\_files: true

Logstash config as below

input {  
beats {  
port =\> 5044  
}  
}

filter {  
mutate {  
gsub =\> ["message", "\r|\n", ""]  
}  
grok {  
match =\> {  
"message" =\> [  
#"[%{TIMESTAMP\_ISO8601:timestamp}] %{DATA:logger}.%{LOGLEVEL:level}: (?[^{]_) %{GREEDYDATA:context}",  
"[%{TIMESTAMP\_ISO8601:timestamp}] %{DATA:logger}.%{LOGLEVEL:level}: (?[^{]_) (?(.|\r|\n)\*) ",  
"%{GREEDYDATA:logmessage}"  
]  
}  
#match =\> ["message", "[%{TIMESTAMP\_ISO8601:timestamp}] %{DATA:logger}.%{LOGLEVEL:level}: %{GREEDYDATA:context}", "%{GREEDYDATA:context}"]  
}  
json {  
source =\> "context"  
target =\> "jsonparsed"  
}  
}

Can someone help me to solve this issue.

Thanks  
sundar

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [March 29, 2019, 11:55am UTC](https://discuss.elastic.co/t/filebeat-multiline-not-working-sundar/173429/2 "2019-03-29T11:55:08Z")

</div>

Could you please format your configuration using `</>`?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 26, 2019, 11:55am UTC](https://discuss.elastic.co/t/filebeat-multiline-not-working-sundar/173429/3 "2019-04-26T11:55:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
