# How to debug multiline in filebeat?

**URL:** <https://discuss.elastic.co/t/how-to-debug-multiline-in-filebeat/195918>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 20, 2019, 11:59am UTC](https://discuss.elastic.co/t/how-to-debug-multiline-in-filebeat/195918 "2019-08-20T11:59:58Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Nee\_Defeng](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nee_defeng/32/45771_2.png) [@Nee\_Defeng](https://discuss.elastic.co/u/Nee_Defeng)\
**Post date:** [August 20, 2019, 11:59am UTC](https://discuss.elastic.co/t/how-to-debug-multiline-in-filebeat/195918/1 "2019-08-20T11:59:58Z")

</div>

Here is my filebeat.yml:

```
filebeat.inputs:

- type: log

  enabled: true

  paths:

    - /home/xyz/nohup.txt

  multiline.pattern: '^\[[0-9]{4}-[0-9]{2}-[0-9]{2}'
  multiline.negate: true
  multiline.match: after

```

Here is the command I used to append the events to the log file:

echo [2019-01-02 1234567 \>\> nohup.txt  
echo [2019-01-02 1234567 \>\> nohup.txt  
echo c\>\> nohup.txt  
echo [2019-01-02 1234567 \>\> nohup.txt

And eventually 'c' was recognized as a new event, so multiline was not working, why?

Thanks for your help.

BTW: How do I debug this?

---

<div class="post-metadata">

**Author:** ![faec](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/faec/32/46988_2.png) [@faec](https://discuss.elastic.co/u/faec)\
**Post date:** [August 22, 2019, 5:56pm UTC](https://discuss.elastic.co/t/how-to-debug-multiline-in-filebeat/195918/2 "2019-08-22T17:56:04Z")

</div>

I think your test was a false negative -- I just tried this configuration and it worked fine on those lines. I think what you're seeing is that when you append the lines with echo, Filebeat reads them as soon as they're added, which means by the time you run `echo c`, the previous line has already been ingested, and it has to start a new one. (I replicated this on my system by delaying slightly between the two echo commands.) If you instead use `cat` to append the multiline entries, or start Filebeat when the entry is already complete, then it seems to work fine.

---

<div class="post-metadata">

**Author:** ![Nee\_Defeng](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nee_defeng/32/45771_2.png) [@Nee\_Defeng](https://discuss.elastic.co/u/Nee_Defeng)\
**Post date:** [August 22, 2019, 10:10pm UTC](https://discuss.elastic.co/t/how-to-debug-multiline-in-filebeat/195918/3 "2019-08-22T22:10:10Z")

</div>

Thanks Fae, you are right, it is working by using 'cat'.

BTW: I thought FileBeat won't send the event until it matches the next pattern, and also it has the timeout property to define how long time it will wait, is it right?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 19, 2019, 10:10pm UTC](https://discuss.elastic.co/t/how-to-debug-multiline-in-filebeat/195918/4 "2019-09-19T22:10:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
