# Filebeat multiline Pattern on Apache Logs does not work as expected (Filebeat -\> Logstash -\> ES)

**URL:** <https://discuss.elastic.co/t/filebeat-multiline-pattern-on-apache-logs-does-not-work-as-expected-filebeat-logstash-es/301747>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [April 6, 2022, 11:44am UTC](https://discuss.elastic.co/t/filebeat-multiline-pattern-on-apache-logs-does-not-work-as-expected-filebeat-logstash-es/301747 "2022-04-06T11:44:47Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Bndlr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bndlr/32/94658_2.png) [@Bndlr](https://discuss.elastic.co/u/Bndlr)\
**Post date:** [April 6, 2022, 11:44am UTC](https://discuss.elastic.co/t/filebeat-multiline-pattern-on-apache-logs-does-not-work-as-expected-filebeat-logstash-es/301747/1 "2022-04-06T11:44:47Z")

</div>

Hello,

if have the following multiline pattern in Filebeat Configuration:

```auto
multiline.pattern: ^((-)*[0-9]{4}-[0-9]{2}-[0-9]{2}|[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3} )

```

to handle mulitline Log Patterns that contains a timestamp first (Tomcats catalina.log) OR an IP Adress like in the Apache Proxy Logs.

With the catalina.log everything work as expected.  
But from the Apache Log a got several LogLines in ONE Message.

 ![filebeat_multiline](https://us1.discourse-cdn.com/elastic/original/3X/4/f/4f92d70e0403f3fbecec3e296122eb171eda5761.png)

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [April 6, 2022, 12:18pm UTC](https://discuss.elastic.co/t/filebeat-multiline-pattern-on-apache-logs-does-not-work-as-expected-filebeat-logstash-es/301747/2 "2022-04-06T12:18:41Z")

</div>

Please share your full `filebeat.yml` file and also a sample of both log types you are collecting.

If the format of your logs are different, you should not use the same multiline pattern.

---

<div class="post-metadata">

**Author:** ![Bndlr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bndlr/32/94658_2.png) [@Bndlr](https://discuss.elastic.co/u/Bndlr)\
**Post date:** [April 7, 2022, 6:23am UTC](https://discuss.elastic.co/t/filebeat-multiline-pattern-on-apache-logs-does-not-work-as-expected-filebeat-logstash-es/301747/3 "2022-04-07T06:23:13Z")

</div>

Filebeat.yml

```auto
filebeat.inputs:
- type: docker
  enabled: true
  containers.ids: '*'

  multiline.pattern: ^((-)*[0-9]{4}-[0-9]{2}-[0-9]{2}|[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3} )
  multiline.negate: true
  multiline.match: after

#============================= Filebeat modules ===============================

filebeat.config.modules:
  # Glob pattern for configuration loading
  path: ${path.config}/modules.d/*.yml

  # Set to true to enable config reloading
  reload.enabled: false

  # Period on which files under path should be checked for changes
  #reload.period: 10s

output.logstash:
 hosts: ["${Elastic_Host}"]

processors:
  - add_docker_metadata:
    labels.dedot: true

```

catalina.log

```auto
2022-04-07 08:20:02,887 [http-nio-8080-exec-77] INFO performance.http.HttpRequest | session.id= | client.ip=192.168.0.115 | request.id= | service.id= | tenant.id= | jobexecution.id= | sourceFeature.name= - /services/de/npm/core/service/cron/trigger/CronTriggerService/executeTrigger took 2488 ms

```

Apache Proxy Log

```auto
192.168.1.93 - - [07/Apr/2022:08:22:05 +0200] "GET /auth/realms/master/metrics HTTP/1.1" 200 3246

```

> If the format of your logs are different, you should not use the same multiline pattern.

The multiline Pattern has an OR Expression so i don't know why this should not work.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 5, 2022, 8:23am UTC](https://discuss.elastic.co/t/filebeat-multiline-pattern-on-apache-logs-does-not-work-as-expected-filebeat-logstash-es/301747/4 "2022-05-05T08:23:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
