# Filebeat process multi-line AND one-line XML

**URL:** <https://discuss.elastic.co/t/filebeat-process-multi-line-and-one-line-xml/142008>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [July 28, 2018, 3:23am UTC](https://discuss.elastic.co/t/filebeat-process-multi-line-and-one-line-xml/142008 "2018-07-28T03:23:05Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![thpoiani](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thpoiani/32/33815_2.png) [@thpoiani](https://discuss.elastic.co/u/thpoiani)\
**Post date:** [July 28, 2018, 3:23am UTC](https://discuss.elastic.co/t/filebeat-process-multi-line-and-one-line-xml/142008/1 "2018-07-28T03:23:05Z")

</div>

Hello guys.  
I have the following filebeat configuration to retrieve XML files.

```
filebeat.prospectors:
    - type: log
      paths:
        - ${LOGGING_FILE}
      multiline.pattern: '.'
      multiline.match: after

```

Each XML should be an event.

That's works **ONLY** if I have an **indented XML**.

How can I retrieve both **indented XML** and **minified XML** (one-line per file)?

---

<div class="post-metadata">

**Author:** ![adrisr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adrisr/32/25423_2.png) [@adrisr](https://discuss.elastic.co/u/adrisr)\
**Post date:** [July 30, 2018, 8:02am UTC](https://discuss.elastic.co/t/filebeat-process-multi-line-and-one-line-xml/142008/2 "2018-07-30T08:02:38Z")

</div>

In my tests, your conf works both for single and multiline files.

Can you check that your single-line files have a newline at the end?

Filebeat requires lines to be correctly terminated, otherwise it will keep waiting in case more data is added to the line.

---

<div class="post-metadata">

**Author:** ![thpoiani](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thpoiani/32/33815_2.png) [@thpoiani](https://discuss.elastic.co/u/thpoiani)\
**Post date:** [July 30, 2018, 12:44pm UTC](https://discuss.elastic.co/t/filebeat-process-multi-line-and-one-line-xml/142008/3 "2018-07-30T12:44:23Z")

</div>

> [@adrisr](#):
>
> Can you check that your single-line files have a newline at the end?

That should be the problem.  
These files don't have newline.

---

<div class="post-metadata">

**Author:** ![adrisr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adrisr/32/25423_2.png) [@adrisr](https://discuss.elastic.co/u/adrisr)\
**Post date:** [July 30, 2018, 12:52pm UTC](https://discuss.elastic.co/t/filebeat-process-multi-line-and-one-line-xml/142008/4 "2018-07-30T12:52:26Z")

</div>

That's the problem 🙂

Filebeat requires lines to be terminated (by a newline). Otherwise, there is no possible way for filebeat to tell if the program writing to the log has finished the line or it was just caught in the middle of writing a line (for programs that use buffering).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 27, 2018, 12:52pm UTC](https://discuss.elastic.co/t/filebeat-process-multi-line-and-one-line-xml/142008/5 "2018-08-27T12:52:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
