# Filebeat multiline splitting events - which timeout to tweak?

**URL:** <https://discuss.elastic.co/t/filebeat-multiline-splitting-events-which-timeout-to-tweak/114427>\
**Category:** Beats\
**Created:** [January 7, 2018, 9:05pm UTC](https://discuss.elastic.co/t/filebeat-multiline-splitting-events-which-timeout-to-tweak/114427 "2018-01-07T21:05:50Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![tehowe](https://avatars.discourse-cdn.com/v4/letter/t/a3d4f5/32.png) [@tehowe](https://discuss.elastic.co/u/tehowe)\
**Post date:** [January 7, 2018, 9:05pm UTC](https://discuss.elastic.co/t/filebeat-multiline-splitting-events-which-timeout-to-tweak/114427/1 "2018-01-07T21:05:50Z")

</div>

Hey, I'm using Filebeat 6.1.1 on a number of Linux hosts. I'm prospecting apt-get logs, which look like this usually

```auto
Start-Date: 2018-01-03 20:45:26
Commandline: /usr/bin/apt-get -y -o Dpkg::Options::=--force-confdef -o Dpkg::Options::=--force-confold dist-upgrade
Upgrade: linux-image-4.9.0-4-amd64:amd64 (4.9.65-3, 4.9.65-3+deb9u1)
End-Date: 2018-01-03 20:45:38

```

Unfortunately in cases where "End-Date" occurs more than a few seconds after "Start-Date" _something_ times out and the End-Date line gets punted into a separate event. Which ends up looking like this

 ![49 PM](https://us1.discourse-cdn.com/elastic/original/3X/0/e/0efb1169df90517b8a638f95b21892171808b601.png)

That's bad. So I attempted to boost the multiline timeout but for some reason this didn't help matters at all. The apt-get and multiline stanza in my filebeat.yml config file currently looks like this.

```auto
- input_type: log
  paths:
    - /var/log/apt/history.log
  fields:
    type: apt
  multiline.pattern: Start-Date
  multiline.negate: true
  multiline.match: after
  multiline.flush_pattern: End-Date
  timeout: 60

```

How should I fix this? Everything I've read online suggests that if you're willing to sacrifice latency by boosting 'the timeout' then this should work. But it doesn't. Is it the wrong timeout? I'm out of ideas ☹

---

<div class="post-metadata">

**Author:** ![adrisr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adrisr/32/25423_2.png) [@adrisr](https://discuss.elastic.co/u/adrisr)\
**Post date:** [January 8, 2018, 4:21am UTC](https://discuss.elastic.co/t/filebeat-multiline-splitting-events-which-timeout-to-tweak/114427/2 "2018-01-08T04:21:29Z")

</div>

You have to set the timeout in the multiline configuration, like this:

`multiline.timeout: 60s`

---

<div class="post-metadata">

**Author:** ![tehowe](https://avatars.discourse-cdn.com/v4/letter/t/a3d4f5/32.png) [@tehowe](https://discuss.elastic.co/u/tehowe)\
**Post date:** [January 8, 2018, 3:59pm UTC](https://discuss.elastic.co/t/filebeat-multiline-splitting-events-which-timeout-to-tweak/114427/3 "2018-01-08T15:59:59Z")

</div>

Thank you! This works. Sometimes it's the little things (like syntax).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 28, 2018, 9:06pm UTC](https://discuss.elastic.co/t/filebeat-multiline-splitting-events-which-timeout-to-tweak/114427/4 "2018-01-28T21:06:11Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
