# Filebeat not seperating events

**URL:** <https://discuss.elastic.co/t/filebeat-not-seperating-events/75191>\
**Category:** Beats\
**Created:** [February 15, 2017, 12:30pm UTC](https://discuss.elastic.co/t/filebeat-not-seperating-events/75191 "2017-02-15T12:30:57Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![gilisade](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gilisade/32/98740_2.png) [@gilisade](https://discuss.elastic.co/u/gilisade)\
**Post date:** [February 15, 2017, 12:30pm UTC](https://discuss.elastic.co/t/filebeat-not-seperating-events/75191/1 "2017-02-15T12:30:57Z")

</div>

Hi  
i have XML log files , each file is 1 XML line  
the problem is that there is no new line afetr each XML (the file ends without an Enter) so filebeat cant ship those lines beacuse he "thinks" there is no end to the event  
i tried using the `close_eof: true` but it didn't work  
only when adding an Enter to the file (new empty line) it manages to ship the XML line

i'm using filebeat 5.0.0

any ideas?

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [February 16, 2017, 2:55pm UTC](https://discuss.elastic.co/t/filebeat-not-seperating-events/75191/2 "2017-02-16T14:55:19Z")

</div>

One potential solution here could be using the `mutiline` feature (even though it is just one line) and use `multiline.timeout`. Because the above is an issue we normally hit with multiline: [https://www.elastic.co/guide/en/beats/filebeat/5.2/configuration-filebeat-options.html#multiline](https://www.elastic.co/guide/en/beats/filebeat/5.2/configuration-filebeat-options.html#multiline)

---

<div class="post-metadata">

**Author:** ![gilisade](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gilisade/32/98740_2.png) [@gilisade](https://discuss.elastic.co/u/gilisade)\
**Post date:** [February 16, 2017, 3:22pm UTC](https://discuss.elastic.co/t/filebeat-not-seperating-events/75191/3 "2017-02-16T15:22:26Z")

</div>

Hi thank you for your response  
We used multiline(without the multiline.timeout option) and it did not work  
Is the multiline.timeout something we must specify or if we use multiline it is by default?

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [February 16, 2017, 3:35pm UTC](https://discuss.elastic.co/t/filebeat-not-seperating-events/75191/4 "2017-02-16T15:35:00Z")

</div>

The default should be set to `5s`.

But TBH I would strongly recommend you to get your logging system to write a new line after the xml event if possible.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [February 20, 2017, 12:50pm UTC](https://discuss.elastic.co/t/filebeat-not-seperating-events/75191/5 "2017-02-20T12:50:16Z")

</div>

@gilisade I tested the part with the timeout and it does not work as I described previously ☹ So best work around is to write a new line into your file after the event.

---

<div class="post-metadata">

**Author:** ![gilisade](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gilisade/32/98740_2.png) [@gilisade](https://discuss.elastic.co/u/gilisade)\
**Post date:** [February 21, 2017, 12:59pm UTC](https://discuss.elastic.co/t/filebeat-not-seperating-events/75191/6 "2017-02-21T12:59:41Z")

</div>

Got it.  
Thank you for trying 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 8, 2017, 12:30pm UTC](https://discuss.elastic.co/t/filebeat-not-seperating-events/75191/7 "2017-03-08T12:30:59Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
