# Filebeat multiline patterns not working

**URL:** <https://discuss.elastic.co/t/filebeat-multiline-patterns-not-working/50478>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 19, 2016, 6:37pm UTC](https://discuss.elastic.co/t/filebeat-multiline-patterns-not-working/50478 "2016-05-19T18:37:22Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![lalu](https://avatars.discourse-cdn.com/v4/letter/l/e480ec/32.png) [@lalu](https://discuss.elastic.co/u/lalu)\
**Post date:** [May 19, 2016, 6:37pm UTC](https://discuss.elastic.co/t/filebeat-multiline-patterns-not-working/50478/1 "2016-05-19T18:37:22Z")

</div>

filebeat v1.2.2 (64 bit)  
OS: centos 6.7

multiline: --\> patterns: --\> '-' --\> pattern: (not working)  
multiline: --\> pattern: (working)

Found detail here:  
(Enhanced LS Config)  
[https://github.com/elastic/filebeat/issues/301](https://github.com/elastic/filebeat/issues/301)

Is this supposed to work or feature not available yet.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [May 20, 2016, 6:35am UTC](https://discuss.elastic.co/t/filebeat-multiline-patterns-not-working/50478/2 "2016-05-20T06:35:39Z")

</div>

Multline support is part of the 1.2 release. The docs can be found here: [https://www.elastic.co/guide/en/beats/filebeat/1.2/configuration-filebeat-options.html#multiline](https://www.elastic.co/guide/en/beats/filebeat/1.2/configuration-filebeat-options.html#multiline)

I'm not sure what you mena with your patterns / pattern above?

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [May 20, 2016, 9:30am UTC](https://discuss.elastic.co/t/filebeat-multiline-patterns-not-working/50478/3 "2016-05-20T09:30:26Z")

</div>

please add some sample logs you want to merge + regex you've configured. I can't even tell what you're trying to do.

---

<div class="post-metadata">

**Author:** ![lalu](https://avatars.discourse-cdn.com/v4/letter/l/e480ec/32.png) [@lalu](https://discuss.elastic.co/u/lalu)\
**Post date:** [May 20, 2016, 5:43pm UTC](https://discuss.elastic.co/t/filebeat-multiline-patterns-not-working/50478/6 "2016-05-20T17:43:20Z")

</div>

![](https://us1.discourse-cdn.com/elastic/original/2X/0/0098663f98c9cfb78d8c93ee85b477e7897c1112.png)

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [May 23, 2016, 10:14am UTC](https://discuss.elastic.co/t/filebeat-multiline-patterns-not-working/50478/7 "2016-05-23T10:14:42Z")

</div>

You've got text instead of pictures. [Here is a script to test your regexes](https://play.golang.org/p/ABEJaX_lsK), but I'm not too keen to type out all these pictures.

Put text in between 3 backticks '`' or use the `</>` button on inserted text in order to code-format your text.

---

<div class="post-metadata">

**Author:** ![lalu](https://avatars.discourse-cdn.com/v4/letter/l/e480ec/32.png) [@lalu](https://discuss.elastic.co/u/lalu)\
**Post date:** [May 23, 2016, 11:13am UTC](https://discuss.elastic.co/t/filebeat-multiline-patterns-not-working/50478/8 "2016-05-23T11:13:50Z")

</div>

I just want to know that the feature is available in Filebeat? The feature I mean more then one pattern in multiline.

---

<div class="post-metadata">

**Author:** ![lalu](https://avatars.discourse-cdn.com/v4/letter/l/e480ec/32.png) [@lalu](https://discuss.elastic.co/u/lalu)\
**Post date:** [May 23, 2016, 11:38am UTC](https://discuss.elastic.co/t/filebeat-multiline-patterns-not-working/50478/9 "2016-05-23T11:38:23Z")

</div>

Thanks Steffen for your trick for formating.

```
multiline:
  pattern: '^Encore.DMS.Svc-'
  negate: true
  match: after

```

This above config works for me for single condition, but not sure about more then one condition like I wrote below.

```
multiline:
  patterns:
    -
      pattern: '^Encore.DMS.Svc-'
      negate: true
      match: after
    -
      pattern: '^Encore.DMS.Svc-\.*RESPONSE:'
      negate: false
      match: after
```

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [May 23, 2016, 12:25pm UTC](https://discuss.elastic.co/t/filebeat-multiline-patterns-not-working/50478/10 "2016-05-23T12:25:57Z")

</div>

multiple conditions are not supported yet. But one can use the `|` (OR-)regex operator in in pattern.

---

<div class="post-metadata">

**Author:** ![lalu](https://avatars.discourse-cdn.com/v4/letter/l/e480ec/32.png) [@lalu](https://discuss.elastic.co/u/lalu)\
**Post date:** [May 23, 2016, 5:52pm UTC](https://discuss.elastic.co/t/filebeat-multiline-patterns-not-working/50478/11 "2016-05-23T17:52:55Z")

</div>

Log content in proper format:

```
Encore.DMS.Svc-6.2-0-1000013856-INFO|08:08:30:246|AgentFirstName : 
Encore.DMS.Svc-6.2-0-1000013856-INFO|08:08:30:315|REQUEST:
<s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/">
  <s:Body ...>
    <h2h-dms-request xmlns=...>
	...
    </h2h-dms-request>
  </s:Body>
</s:Envelope>
Encore.DMS.Svc-6.2-0-1000013856-INFO|08:08:30:730|RESPONSE:
<soapenv:Envelope ...>
  <s:Header xmlns:s=... />
  <soapenv:Body>
    <xrsi:h2h-dms-reply xmlns:xrsi=...>
	...
    </xrsi:h2h-dms-reply>
  </soapenv:Body>
</soapenv:Envelope>
Encore.DMS.Svc-6.2-0-1000013856-INFO|08:08:30:730|Return value:
Encore.DMS.Svc-6.2-0-1000013856-INFO|08:08:30:731|	
Encore.DMS.Svc-6.2-0-1000013856-INFO|08:08:30:731|Code : 000
```

---

<div class="post-metadata">

**Author:** ![lalu](https://avatars.discourse-cdn.com/v4/letter/l/e480ec/32.png) [@lalu](https://discuss.elastic.co/u/lalu)\
**Post date:** [May 23, 2016, 5:56pm UTC](https://discuss.elastic.co/t/filebeat-multiline-patterns-not-working/50478/12 "2016-05-23T17:56:19Z")

</div>

Thanks for your help.  
I already have this config and it is working as expected.

```
multiline:
  pattern: '(^Encore.DMS.Svc-)|(^Encore.DMS.Web-)|(^Encore.DASMonitor-)'
  negate: true
  match: after

```

But for my last condition I need to negate inside the regex. Which I think is not allowed or will not work because negate handled in separate line like "negate: true".  
"`! (^Encore.DMS.Svc-\.*RESPONSE:)`"  
Something like above can be doable or any other way this can be achieved in Filebeat?

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [May 24, 2016, 8:53pm UTC](https://discuss.elastic.co/t/filebeat-multiline-patterns-not-working/50478/13 "2016-05-24T20:53:34Z")

</div>

Do I understand you correctly? You just want to merge REQUEST plus RESPONSE attributes?

Check out this solution: [https://play.golang.org/p/IS8wDp1h6F](https://play.golang.org/p/IS8wDp1h6F)  
Regex is `^([[:space:]]|<|(.*\|){2}RESPONSE)`  
First sub-term matches a string starting with whitespace, the second sub-term matches a line starting with `<` and the third subfilter matches `... | ... |RESPONSE` without even checking the content of the columns.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 9:51pm UTC](https://discuss.elastic.co/t/filebeat-multiline-patterns-not-working/50478/14 "2017-07-05T21:51:33Z")

</div>


