# Filebeat not sending empty lines

**URL:** <https://discuss.elastic.co/t/filebeat-not-sending-empty-lines/118060>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [February 1, 2018, 4:04pm UTC](https://discuss.elastic.co/t/filebeat-not-sending-empty-lines/118060 "2018-02-01T16:04:23Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![dmontemayors](https://avatars.discourse-cdn.com/v4/letter/d/2acd7d/32.png) [@dmontemayors](https://discuss.elastic.co/u/dmontemayors)\
**Post date:** [February 1, 2018, 4:04pm UTC](https://discuss.elastic.co/t/filebeat-not-sending-empty-lines/118060/1 "2018-02-01T16:04:23Z")

</div>

Hi all,

I looked around and it seems like filebeat should be sending empty lines in the log files. Running version 6.1.3 with a pretty basic configuration but it looks like the harvester is ignoring them. Am I missing something?

Config file:

```
filebeat.prospectors:
- type: log
  enabled: true
  paths:
    - /usr/*.log

filebeat.config.modules:
  path: ${path.config}/modules.d/*.yml
  reload.enabled: false

output.logstash:
  # The Logstash hosts
  hosts: ["localhost:5044"]

```

Test file:

```
hello

the lines above are ignored.

```

Run with command line (debug mode):

/usr/share/filebeat/bin/filebeat -e -d "\*" -c /etc/filebeat/filebeat.yml -path.home /usr/share/filebeat -path.config /etc/filebeat -path.data /var/lib/filebeat -path.logs /var/log/filebeat

Events published (notice empty lines not published):

```
2018/02/01 15:55:11.560440 processor.go:275: DBG [publish] Publish event: {
  "@timestamp": "2018-02-01T15:55:11.560Z",
  "@metadata": {
    "beat": "filebeat",
    "type": "doc",
    "version": "6.1.3"
  },
  "offset": 6,
  "message": "hello",
  "prospector": {
    "type": "log"
  },
  "beat": {
    "name": "myhost",
    "hostname": "myhost",
    "version": "6.1.3"
  },
  "source": "/usr/test2.log"
}
2018/02/01 15:55:11.560507 processor.go:275: DBG [publish] Publish event: {
  "@timestamp": "2018-02-01T15:55:11.560Z",
  "@metadata": {
    "beat": "filebeat",
    "type": "doc",
    "version": "6.1.3"
  },
  "source": "/usr/test2.log",
  "offset": 37,
  "message": "the lines above are ignored.",
  "prospector": {
    "type": "log"
  },
  "beat": {
    "hostname": "myhost",
    "version": "6.1.3",
    "name": "myhost"
  }
}

```

Thank you.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 1, 2018, 11:19pm UTC](https://discuss.elastic.co/t/filebeat-not-sending-empty-lines/118060/2 "2018-02-01T23:19:54Z")

</div>

Are you suggesting that those are part of the same event, and that you have multiline messages with empty CR/LFs in them?

---

<div class="post-metadata">

**Author:** ![dmontemayors](https://avatars.discourse-cdn.com/v4/letter/d/2acd7d/32.png) [@dmontemayors](https://discuss.elastic.co/u/dmontemayors)\
**Post date:** [February 2, 2018, 3:10pm UTC](https://discuss.elastic.co/t/filebeat-not-sending-empty-lines/118060/3 "2018-02-02T15:10:17Z")

</div>

For the above I simply copied the test file into the directory being watched by FileBeat to produce those results. From what I've seen I generally have events that consist of single empty lines (e.g. a program may simply 'printf("\n")' into a log file). I am trying to reconstruct that log file at the receiving end, but FileBeat is leaving out the newlines so my files aren't matching.

---

<div class="post-metadata">

**Author:** ![dmontemayors](https://avatars.discourse-cdn.com/v4/letter/d/2acd7d/32.png) [@dmontemayors](https://discuss.elastic.co/u/dmontemayors)\
**Post date:** [February 14, 2018, 3:43pm UTC](https://discuss.elastic.co/t/filebeat-not-sending-empty-lines/118060/4 "2018-02-14T15:43:26Z")

</div>

Should I open an issue in github before this thread auto closes?

---

<div class="post-metadata">

**Author:** ![tudor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor/32/3753_2.png) [@tudor](https://discuss.elastic.co/u/tudor)\
**Post date:** [February 16, 2018, 9:53am UTC](https://discuss.elastic.co/t/filebeat-not-sending-empty-lines/118060/5 "2018-02-16T09:53:08Z")

</div>

It seems to be indeed the case that empty lines are ignored. But what is your use case for needing empty lines? Seems that in the logging use case they are not exactly useful.

Playing around with the multiline config, it is possible to append the empty lines to the previous line, so that they don't create a a dedicated event, but they are not completely lost either. This is the multiline config that I tried:

```auto
  multiline.pattern: '^$'
  multiline.match: after

```

---

<div class="post-metadata">

**Author:** ![dmontemayors](https://avatars.discourse-cdn.com/v4/letter/d/2acd7d/32.png) [@dmontemayors](https://discuss.elastic.co/u/dmontemayors)\
**Post date:** [February 16, 2018, 3:35pm UTC](https://discuss.elastic.co/t/filebeat-not-sending-empty-lines/118060/6 "2018-02-16T15:35:58Z")

</div>

Thank you for looking. I will try the multiline pattern. Our use case is to rebuild the log files to their original format after processing. The empty lines keep the formatting of the file intact and make it easier to read should we need to examine them later.

The documentation seems to indicate these lines shouldn't be ignored. Is there something to be fixed or should the documentation be updated?

---

<div class="post-metadata">

**Author:** ![tudor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor/32/3753_2.png) [@tudor](https://discuss.elastic.co/u/tudor)\
**Post date:** [February 22, 2018, 3:22pm UTC](https://discuss.elastic.co/t/filebeat-not-sending-empty-lines/118060/7 "2018-02-22T15:22:15Z")

</div>

Can you open a ticket to report the documentation issue, please?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 22, 2018, 4:04pm UTC](https://discuss.elastic.co/t/filebeat-not-sending-empty-lines/118060/8 "2018-02-22T16:04:40Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 22, 2018, 9:29pm UTC](https://discuss.elastic.co/t/filebeat-not-sending-empty-lines/118060/9 "2018-02-22T21:29:29Z")

</div>



---

<div class="post-metadata">

**Author:** ![dmontemayors](https://avatars.discourse-cdn.com/v4/letter/d/2acd7d/32.png) [@dmontemayors](https://discuss.elastic.co/u/dmontemayors)\
**Post date:** [February 26, 2018, 6:04pm UTC](https://discuss.elastic.co/t/filebeat-not-sending-empty-lines/118060/10 "2018-02-26T18:04:20Z")

</div>

[https://github.com/elastic/beats/issues/6476](https://github.com/elastic/beats/issues/6476) Thank you.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 18, 2020, 11:29pm UTC](https://discuss.elastic.co/t/filebeat-not-sending-empty-lines/118060/11 "2020-08-18T23:29:25Z")

</div>


