# Filebeat multiline pattern from 'abbbc' to 'ac'

**URL:** <https://discuss.elastic.co/t/filebeat-multiline-pattern-from-abbbc-to-ac/229267>\
**Category:** Beats\
**Tags:** windows, filebeat\
**Created:** [April 22, 2020, 1:03pm UTC](https://discuss.elastic.co/t/filebeat-multiline-pattern-from-abbbc-to-ac/229267 "2020-04-22T13:03:06Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![CorneM](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cornem/32/45664_2.png) [@CorneM](https://discuss.elastic.co/u/CorneM)\
**Post date:** [April 22, 2020, 1:03pm UTC](https://discuss.elastic.co/t/filebeat-multiline-pattern-from-abbbc-to-ac/229267/1 "2020-04-22T13:03:06Z")

</div>

Hello all,

The last few days I have been struggling with a multiline pattern. My multiline log messages have a pattern like 'abbbc'. I don't need the b-parts to be send to LogStash. So basically what I want to accomplish is to convert a multiline log message like

```auto
a
b
b
b
c

```

into

`ac`

Unfortunately the "exclude\_lines" parameter is handled after the "multiline.pattern" parameter in the filebeat.yml.

Any ideas on how to crack this case?

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [April 22, 2020, 8:25pm UTC](https://discuss.elastic.co/t/filebeat-multiline-pattern-from-abbbc-to-ac/229267/2 "2020-04-22T20:25:40Z")

</div>

How about using Filebeat just for the `exclude_lines` part and having it send the rest of the lines to Logstash as single events? And then using the Logstash [`multiline` codec](https://www.elastic.co/guide/en/logstash/current/plugins-codecs-multiline.html) on the `beats` input?

---

<div class="post-metadata">

**Author:** ![CorneM](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cornem/32/45664_2.png) [@CorneM](https://discuss.elastic.co/u/CorneM)\
**Post date:** [April 23, 2020, 11:27am UTC](https://discuss.elastic.co/t/filebeat-multiline-pattern-from-abbbc-to-ac/229267/3 "2020-04-23T11:27:05Z")

</div>

That could be a solution. However I'm not in control of LogStash. I work in a fairly large company and each team has certain responsibilities. LogStash is a service from another team. So I'd rather solve this within a Filebeat configuration (if possible).

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [April 23, 2020, 2:18pm UTC](https://discuss.elastic.co/t/filebeat-multiline-pattern-from-abbbc-to-ac/229267/4 "2020-04-23T14:18:19Z")

</div>

I see. Then how about using two Filebeat instances? The first one could read from your log file, use `exclude_lines` to exclude the `b` lines, and use the `file` output to write to intermediate log files. The second one could read from this intermediate log file, use `multiline`, and send the resulting events to Logstash.

You would probably want to write intermediate log files by day or by hour so you can have something come around and clean them up periodically.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 21, 2020, 2:18pm UTC](https://discuss.elastic.co/t/filebeat-multiline-pattern-from-abbbc-to-ac/229267/5 "2020-05-21T14:18:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
