# Filebeats multiline pattern help

**URL:** <https://discuss.elastic.co/t/filebeats-multiline-pattern-help/144955>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 17, 2018, 7:34pm UTC](https://discuss.elastic.co/t/filebeats-multiline-pattern-help/144955 "2018-08-17T19:34:55Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![fionamacd](https://avatars.discourse-cdn.com/v4/letter/f/6a8cbe/32.png) [@fionamacd](https://discuss.elastic.co/u/fionamacd)\
**Post date:** [August 17, 2018, 7:34pm UTC](https://discuss.elastic.co/t/filebeats-multiline-pattern-help/144955/1 "2018-08-17T19:34:55Z")

</div>

Hi,  
I have some log files I want to parse in Filebeat and can't get the multiline.pattern options to work for my logs. All the sites I tested the regex and data at show it should match, but I get mixed up message entries in elasticsearch trying this.

Here is sample of 2 logs entries where I want each one to parse as a single message:

Date Time: 2017-05-03 15:11:25  
Server Name: LEFFER-SB-02B  
Agent ID: 14  
User Name: LEFFER-SB-02B$  
Error Number: -1  
Error Description: 1The operation has timed outSystem.Net.WebException: The operation has timed out  
at System.Net.HttpWebRequest.GetResponse()  
at W6IntOutMsgLib.W6IntOutMsgGW.SendHTTPMessage(String& strMessage, String& strUrl, Boolean blnQueryString, Boolean blnAsync, String strSoapAction, String password, String userName, String domain, X509Certificate2 clientCertificate)  
Error Source: W6IntUtilsLibGW.clsAgent.ProcessPendingMessages  
Outgoing Message Key: 106991662  
Incoming Message:

Date Time: 2017-05-03 15:13:09  
Server Name: LEFFER-SB-02B  
Agent ID: 14  
User Name: LEFFER-SB-02B$  
Error Number: -1  
Error Description: 1The request was aborted: The operation has timed out.System.Net.WebException: The request was aborted: The operation has timed out.  
at System.Net.HttpWebRequest.GetResponse()  
at W6IntOutMsgLib.W6IntOutMsgGW.SendHTTPMessage(String& strMessage, String& strUrl, Boolean blnQueryString, Boolean blnAsync, String strSoapAction, String password, String userName, String domain, X509Certificate2 clientCertificate)  
Error Source: W6IntUtilsLibGW.clsAgent.ProcessPendingMessages  
Outgoing Message Key: 106991663  
Incoming Message:

I couldn't figure out a way to get the blank line recognized as the break point between them. So I set up my filebeat.yml for this input file:  
filebeat.inputs:

- type: log  
enabled: true  
tags:  
["this\_is\_log3", "integration", "- type: log  
enabled: true  
tags:  
["this\_is\_log3", "integration", "LEDCOR", "outgoing"]  
paths:
  - C:\Temp\test\_logs\W6IntLogOutgoing\*  
multiline.pattern: '/^Date Time:(?:.\*)/'  
multiline.negate: true  
multiline.match: after  
multiline.max\_lines: 12000", "outgoing"]  
paths:
  - C:\Temp\test\_logs\W6IntLogOutgoing\*  
multiline.pattern: '/^Date Time:(?:.\*)/'  
multiline.negate: true  
multiline.match: after  
multiline.max\_lines: 12000

When I look at it in Elasticsearch it just shows as one entry:  
message Date Time: 2017-05-03 15:11:25 Server Name: LEFFER-SB-02B Agent ID: 14 User Name: LEFFER-SB-02B$ Error Number: -1 Error Description: \<MessageResult Status="2"\>\<Number\>1\</Number\>\<Description\>The operation has timed out\</Description\>\<Source\>System.Net.WebException: The operation has timed out at System.Net.HttpWebRequest.GetResponse() at W6IntOutMsgLib.W6IntOutMsgGW.SendHTTPMessage(String&amp; strMessage, String&amp; strUrl, Boolean blnQueryString, Boolean blnAsync, String strSoapAction, String password, String userName, String domain, X509Certificate2 clientCertificate)\</Source\>\</MessageResult\> Error Source: W6IntUtilsLibGW.clsAgent.ProcessPendingMessages Outgoing Message Key: 106991662 Incoming Message: Date Time: 2017-05-03 15:13:09 Server Name: LEFFER-SB-02B Agent ID: 14 User Name: LEFFER-SB-02B$ Error Number: -1 Error Description: \<MessageResult Status="2"\>\<Number\>1\</Number\>\<Description\>The request was aborted: The operation has timed out.\</Description\>\<Source\>System.Net.WebException: The request was aborted: The operation has timed out. at System.Net.HttpWebRequest.GetResponse() at W6IntOutMsgLib.W6IntOutMsgGW.SendHTTPMessage(String&amp; strMessage, String&amp; strUrl, Boolean blnQueryString, Boolean blnAsync, String strSoapAction, String password, String userName, String domain, X509Certificate2 clientCertificate)\</Source\>\</MessageResult\> Error Source: W6IntUtilsLibGW.clsAgent.ProcessPendingMessages Outgoing Message Key: 106991663 Incoming Message:

How can I make filebeat split the logs into 2 messages/events?

Thanks,  
Fiona  
filebeat version 6.3.2

---

<div class="post-metadata">

**Author:** ![fionamacd](https://avatars.discourse-cdn.com/v4/letter/f/6a8cbe/32.png) [@fionamacd](https://discuss.elastic.co/u/fionamacd)\
**Post date:** [August 20, 2018, 12:43pm UTC](https://discuss.elastic.co/t/filebeats-multiline-pattern-help/144955/2 "2018-08-20T12:43:37Z")

</div>

> [@fionamacd](#):
>
> multiline.pattern: '/^Date Time:(?:.\*)/'

Never mind, I found the issue. The pattern had / in it which I removed and it started matching and processing the logs correctly.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 17, 2018, 12:43pm UTC](https://discuss.elastic.co/t/filebeats-multiline-pattern-help/144955/3 "2018-09-17T12:43:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
