# Filebeat multiline with line breaks

**URL:** <https://discuss.elastic.co/t/filebeat-multiline-with-line-breaks/88105>\
**Category:** Beats\
**Created:** [June 2, 2017, 3:24pm UTC](https://discuss.elastic.co/t/filebeat-multiline-with-line-breaks/88105 "2017-06-02T15:24:13Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![amruthapbhat](https://avatars.discourse-cdn.com/v4/letter/a/8491ac/32.png) [@amruthapbhat](https://discuss.elastic.co/u/amruthapbhat)\
**Post date:** [June 2, 2017, 3:24pm UTC](https://discuss.elastic.co/t/filebeat-multiline-with-line-breaks/88105/1 "2017-06-02T15:24:13Z")

</div>

I have a file in the below format  
Ex:

This is the first line.

This is the second line.  
I am using no pattern since I want all the lines in the text to send to Logstash which is around 2000 lines.

If the file is in the below format it works.  
Ex:

This is the first line.  
This is the second line.  
If the file is in the above format multiline works.

Could you please help me out with this.

---

<div class="post-metadata">

**Author:** ![exekias](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/exekias/32/28718_2.png) [@exekias](https://discuss.elastic.co/u/exekias)\
**Post date:** [June 5, 2017, 6:33am UTC](https://discuss.elastic.co/t/filebeat-multiline-with-line-breaks/88105/2 "2017-06-05T06:33:20Z")

</div>

Hi @amruthapbhat,

Could you please share your filebeat.yml settings? It should help diagnosing your issue

---

<div class="post-metadata">

**Author:** ![amruthapbhat](https://avatars.discourse-cdn.com/v4/letter/a/8491ac/32.png) [@amruthapbhat](https://discuss.elastic.co/u/amruthapbhat)\
**Post date:** [June 5, 2017, 6:48am UTC](https://discuss.elastic.co/t/filebeat-multiline-with-line-breaks/88105/3 "2017-06-05T06:48:12Z")

</div>

filebeat:  
prospectors:

```
-
  paths:
    - /home/ubuntu/containers.d/*/*.log

  input_type: log

  document_type: syslog

  multiline:
    match: after
    max_lines: 2000
```

---

<div class="post-metadata">

**Author:** ![amruthapbhat](https://avatars.discourse-cdn.com/v4/letter/a/8491ac/32.png) [@amruthapbhat](https://discuss.elastic.co/u/amruthapbhat)\
**Post date:** [June 5, 2017, 6:58am UTC](https://discuss.elastic.co/t/filebeat-multiline-with-line-breaks/88105/4 "2017-06-05T06:58:14Z")

</div>

Hi @exekias,

Please find the above prospectors

---

<div class="post-metadata">

**Author:** ![exekias](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/exekias/32/28718_2.png) [@exekias](https://discuss.elastic.co/u/exekias)\
**Post date:** [June 5, 2017, 12:13pm UTC](https://discuss.elastic.co/t/filebeat-multiline-with-line-breaks/88105/5 "2017-06-05T12:13:08Z")

</div>

uhm, now I see this I'm wondering, what are you looking for?

Are you trying to send all lines **in the same event**? You don't need to set a multiline pattern to send all file lines, they will be sent one by one.

Could you please clarify what do you want to achieve?

---

<div class="post-metadata">

**Author:** ![amruthapbhat](https://avatars.discourse-cdn.com/v4/letter/a/8491ac/32.png) [@amruthapbhat](https://discuss.elastic.co/u/amruthapbhat)\
**Post date:** [June 5, 2017, 1:42pm UTC](https://discuss.elastic.co/t/filebeat-multiline-with-line-breaks/88105/6 "2017-06-05T13:42:19Z")

</div>

Hi @exekias,

I have a log file which could have around 1000 lines of content along with line breaks. i want to display the entire file as one event

---

<div class="post-metadata">

**Author:** ![amruthapbhat](https://avatars.discourse-cdn.com/v4/letter/a/8491ac/32.png) [@amruthapbhat](https://discuss.elastic.co/u/amruthapbhat)\
**Post date:** [June 5, 2017, 5:06pm UTC](https://discuss.elastic.co/t/filebeat-multiline-with-line-breaks/88105/7 "2017-06-05T17:06:32Z")

</div>

Hi @exekias,  
The log files works correctly if there are no line breaks with the above configs. It displays the entire 1000 lines of content as a single log. The issue is when i have line breaks

---

<div class="post-metadata">

**Author:** ![exekias](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/exekias/32/28718_2.png) [@exekias](https://discuss.elastic.co/u/exekias)\
**Post date:** [June 6, 2017, 9:53am UTC](https://discuss.elastic.co/t/filebeat-multiline-with-line-breaks/88105/8 "2017-06-06T09:53:48Z")

</div>

I think you need to set a multiline pattern like this:

`multiline.pattern: '.'`

---

<div class="post-metadata">

**Author:** ![amruthapbhat](https://avatars.discourse-cdn.com/v4/letter/a/8491ac/32.png) [@amruthapbhat](https://discuss.elastic.co/u/amruthapbhat)\
**Post date:** [June 6, 2017, 10:59am UTC](https://discuss.elastic.co/t/filebeat-multiline-with-line-breaks/88105/9 "2017-06-06T10:59:37Z")

</div>

Hi @exekias,

i have given a link below where i have placed a sample log.

Link to the Dockerlog:

> <https://github.com/amruthapbhat/java-maven-junit-helloworld/blob/master/Dockerfile.log>

Please let me know if there is any pattern to combine all the lines into one event

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [June 7, 2017, 10:04am UTC](https://discuss.elastic.co/t/filebeat-multiline-with-line-breaks/88105/10 "2017-06-07T10:04:45Z")

</div>

Have you tried the multiline tester link from our docs? e.g. setting the regex pattern to `^.|^$` does help: [https://play.golang.org/p/fsNzzM8bHA](https://play.golang.org/p/fsNzzM8bHA)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 23, 2017, 3:32pm UTC](https://discuss.elastic.co/t/filebeat-multiline-with-line-breaks/88105/11 "2017-06-23T15:32:24Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
