# Filebeat on Windows Server R2 2008 Issue

**URL:** <https://discuss.elastic.co/t/filebeat-on-windows-server-r2-2008-issue/179821>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 6, 2019, 5:11pm UTC](https://discuss.elastic.co/t/filebeat-on-windows-server-r2-2008-issue/179821 "2019-05-06T17:11:16Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ganesh999](https://avatars.discourse-cdn.com/v4/letter/g/a88e4f/32.png) [@Ganesh999](https://discuss.elastic.co/u/Ganesh999)\
**Post date:** [May 6, 2019, 5:11pm UTC](https://discuss.elastic.co/t/filebeat-on-windows-server-r2-2008-issue/179821/1 "2019-05-06T17:11:16Z")

</div>

Hi All,

Have been setting filebeat on Windows Server 2008 . The filebeat is installed as service but the problem here is using the multiline .  
While parsing the same file through logstash it is parsing properly with the multiline codec in file input but while using filebeat the multiline doesn't work as expected it brings the whole file in a single message.  
While going through the forum found that it doesn't support Windows 2008  
Just t need help on this.

Log file sample

Application name:  
Application type: CFGGVPMCP (145)  
Command line: pwcallmgr.exe -service vpMediaControl64 -app MUM\_MediaControlPlatform\_1 -host HYDDCGENCME1 -port 2020 -sstart  
Host name: MUMCCGENMCP1  
Start time (UTC): 2019-04-16T15:33:16  
Running time: 2:15:25:57  
Host info: Windows 6.1.7601, 2, Service Pack 1, 1.0, 0112, 3  
File: (652) E:\Ged\MUM\_MCP

2019-04-19T12:29:13.402 Int 50035 00A901CB-10E79A18 4460 log varStmntToDate = \*\*\*\*\*   
2019-04-19T12:29:13.402 Int 50035 00A901CB-10E79A18 4460 log varPaymentDueDate =\*\*\*\*\*  
2019-04-19T12:29:13.402 Int 50035 00A901CB-10E79A18 4460 log varPaymentDueDate =\*\*\*\*\*

For Logstash multiline config  
codec =\> multiline {  
pattern =\> "^%{TIMESTAMP\_ISO8601}"  
negate =\> true  
what =\> "previous"  
}  
For Filebeat multiline  
multiline.pattern: '^%{TIMESTAMP\_ISO8601}'  
multiline.negate: true  
multiline.match: after

---

<div class="post-metadata">

**Author:** ![martinr\_ubi](https://avatars.discourse-cdn.com/v4/letter/m/b5e925/32.png) [@martinr\_ubi](https://discuss.elastic.co/u/martinr_ubi)\
**Post date:** [May 6, 2019, 9:38pm UTC](https://discuss.elastic.co/t/filebeat-on-windows-server-r2-2008-issue/179821/2 "2019-05-06T21:38:52Z")

</div>

Hi,

Your multiline pattern is not valid for filebeat because your using a named grok pattern. Logstash multiline codec supports the named grok pattern that come in a file. look at the logstash doc for the multiline codec and you’ll see that it claims support for grok named pattern.

In filebeat you need to write the real regex and you can’t reference a grok named pattern. filebeat has no clue what this is: %{TIMESTAMP\_ISO8601}. Logstash does because it fetches the real regex from the named pattern file.

---

<div class="post-metadata">

**Author:** ![Ganesh999](https://avatars.discourse-cdn.com/v4/letter/g/a88e4f/32.png) [@Ganesh999](https://discuss.elastic.co/u/Ganesh999)\
**Post date:** [May 7, 2019, 9:19am UTC](https://discuss.elastic.co/t/filebeat-on-windows-server-r2-2008-issue/179821/3 "2019-05-07T09:19:50Z")

</div>

Hi @martinr_ubi ,

Thanks it worked gracefully.  
But I was applying same grok time on windows 10 where filebeat 6.3.1 is present and its working over there.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 4, 2019, 9:19am UTC](https://discuss.elastic.co/t/filebeat-on-windows-server-r2-2008-issue/179821/4 "2019-06-04T09:19:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
