# Getting multiline to work

**URL:** <https://discuss.elastic.co/t/getting-multiline-to-work/139020>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [July 7, 2018, 5:36pm UTC](https://discuss.elastic.co/t/getting-multiline-to-work/139020 "2018-07-07T17:36:47Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Magnus\_Therning](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnus_therning/32/33091_2.png) [@Magnus\_Therning](https://discuss.elastic.co/u/Magnus_Therning)\
**Post date:** [July 7, 2018, 5:36pm UTC](https://discuss.elastic.co/t/getting-multiline-to-work/139020/1 "2018-07-07T17:36:47Z")

</div>

I have another [question on getting `mulitline` to work with _syslog_](https://discuss.elastic.co/t/syslog-multiline-and-docker-compose/139010), but I thought I'd simplify my configuration a little and remove _syslog_ from the equation.

The Docker Compose config for the _filebeat_ container is

```auto
  filebeat:
    image: docker.elastic.co/beats/filebeat:6.3.1
    stdin_open: true
    tty: true
    command: filebeat -v -c /config-dir/filebeat.yml
    restart: always
    volumes:
      - ./log-cfg/filebeat.yml:/config-dir/filebeat.yml
      - ./beat-in/:/beat-in/

```

and the _filebeat_ configuration is

```auto
filebeat.inputs:
  - type: log
    paths:
      - /beat-in/*.log
    multiline:
      pattern: '^[[:space]]'
      negate: false
      match: after

output:
  console.pretty: false

```

After a `docker-compose up filebeat` I open a second terminal and run

```auto
cat <<EOF > ./beat-in/foo.log
2018-07-07 foo
  bar
EOF

```

The two added lines are picked up by _filebeat_, but I get two messages out, despite the `multiline` configuration above:

```auto
{"@timestamp":"2018-07-07T17:36:03.793Z","@metadata":{"beat":"filebeat","type":"doc","version":"6.3.1"},"offset":38,"message":"2018-07-07 foo","source":"/beat-in/foo.log","prospector":{"type":"log"},"input":{"type":"log"},"beat":{"hostname":"4e19f393b815","version":"6.3.1","name":"4e19f393b815"},"host":{"name":"4e19f393b815"}}
{"@timestamp":"2018-07-07T17:36:03.793Z","@metadata":{"beat":"filebeat","type":"doc","version":"6.3.1"},"source":"/beat-in/foo.log","offset":53,"message":" bar","prospector":{"type":"log"},"input":{"type":"log"},"beat":{"name":"4e19f393b815","hostname":"4e19f393b815","version":"6.3.1"},"host":{"name":"4e19f393b815"}}

```

Clearly I'm missing something here, but what?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [July 8, 2018, 1:43pm UTC](https://discuss.elastic.co/t/getting-multiline-to-work/139020/2 "2018-07-08T13:43:11Z")

</div>

> [@Magnus\_Therning](#):
>
> pattern: '\[1\]'

I noticed that it works if I use `'^\s'` instead of `'^[[:space]]'`. Does that also work for you?

* * *

1. [:space]

---

<div class="post-metadata">

**Author:** ![Magnus\_Therning](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnus_therning/32/33091_2.png) [@Magnus\_Therning](https://discuss.elastic.co/u/Magnus_Therning)\
**Post date:** [July 8, 2018, 2:29pm UTC](https://discuss.elastic.co/t/getting-multiline-to-work/139020/3 "2018-07-08T14:29:04Z")

</div>

Indeed, `^\s` does work, and `^[[:space:]]` works too (notice the colon I missed in my config! 🤦‍♂️ Thanks for helping me find my stupid mistake!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 5, 2018, 2:37pm UTC](https://discuss.elastic.co/t/getting-multiline-to-work/139020/4 "2018-08-05T14:37:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
