# Filebeat not publishing multi-line event after timeout

**URL:** <https://discuss.elastic.co/t/filebeat-not-publishing-multi-line-event-after-timeout/137235>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [June 25, 2018, 11:06am UTC](https://discuss.elastic.co/t/filebeat-not-publishing-multi-line-event-after-timeout/137235 "2018-06-25T11:06:28Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![dev.net](https://avatars.discourse-cdn.com/v4/letter/d/54ee81/32.png) [@dev.net](https://discuss.elastic.co/u/dev.net)\
**Post date:** [June 25, 2018, 11:06am UTC](https://discuss.elastic.co/t/filebeat-not-publishing-multi-line-event-after-timeout/137235/1 "2018-06-25T11:06:28Z")

</div>

Hi,

I have configured filebeat with a multi line pattern to watch log files that will be written to once and contain a single root XML element with no XML declaration. Sometimes the root XML element can span multiple lines and sometimes it can span a single line.

close\_eof: true  
ignore\_older: 5m  
clean\_inactive: 10m  
multiline.pattern: ^\<error.\*  
multiline.negate: true  
multiline.match: after  
multiline.flush: \</error\>  
multiline.timeout: 5s

If the XML element is all on a single line then the multiline flush pattern will not be present and I have configured a timeout to flush the event anyway. The config works when the xml file has multiple lines but doesn't work when there is only a single line.

I can see from the debug logs that the event is being flushed due to the timeout but nothing is actually published. Unfortunately the XML file doesn't end every line with CRLF.

Can I make this work for a file with a single XML element on a single line that has no CRLF?

Thanks

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [June 25, 2018, 3:07pm UTC](https://discuss.elastic.co/t/filebeat-not-publishing-multi-line-event-after-timeout/137235/2 "2018-06-25T15:07:00Z")

</div>

Hi @dev.net and welcome 🙂

I think this can be a case of this issue [https://github.com/elastic/beats/issues/1324](https://github.com/elastic/beats/issues/1324).  
As a workaround, would there be any chance you can make your application to always write a new line after the XML?

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [June 25, 2018, 3:18pm UTC](https://discuss.elastic.co/t/filebeat-not-publishing-multi-line-event-after-timeout/137235/3 "2018-06-25T15:18:02Z")

</div>

Filebeat needs lines to be terminated by `\n`.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 23, 2018, 3:24pm UTC](https://discuss.elastic.co/t/filebeat-not-publishing-multi-line-event-after-timeout/137235/4 "2018-07-23T15:24:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
