# How to define multiline in filebeat.inputs base on image?

**URL:** <https://discuss.elastic.co/t/how-to-define-multiline-in-filebeat-inputs-base-on-image/314780>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [September 20, 2022, 1:50pm UTC](https://discuss.elastic.co/t/how-to-define-multiline-in-filebeat-inputs-base-on-image/314780 "2022-09-20T13:50:26Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![amir\_Bialek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/amir_bialek/32/109973_2.png) [@amir\_Bialek](https://discuss.elastic.co/u/amir_Bialek)\
**Post date:** [September 20, 2022, 1:50pm UTC](https://discuss.elastic.co/t/how-to-define-multiline-in-filebeat-inputs-base-on-image/314780/1 "2022-09-20T13:50:26Z")

</div>

Hey, in our cluster some apps are sending logs as multiline, and the problem is that the log structure is different from app to app.

How can we set up an 'if' condition that will include the

```auto
        multiline.pattern: '^[0-9]{4}-[0-9]{2}-[0-9]{2}'
        multiline.negate: true
        multiline.match: after

```

In it?

Our code:

```auto
  filebeatConfig:
    filebeat.yml: |
      filebeat.inputs:
      - type: container
        paths:
          - /var/log/containers/*.log
        processors:
        - add_kubernetes_metadata:
            host: ${NODE_NAME}
            matchers:
            - logs_path:
                logs_path: "/var/log/containers/"
        - drop_event:
            when:
              contains:
                container.image.name: "kibana"
              

      output.logstash:
        hosts: ["logstash-listener:5044"]

```

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 21, 2022, 1:34am UTC](https://discuss.elastic.co/t/how-to-define-multiline-in-filebeat-inputs-base-on-image/314780/2 "2022-09-21T01:34:22Z")

</div>

Multiline will only apply if it **doesn't** detect the start of your pattern. That means you can define the pattern and it'll skip individual entries. [The docs](https://www.elastic.co/guide/en/beats/filebeat/current/multiline-examples.html#multiline) mention this;

> Filebeat takes all the lines that do not start with `[` and combines them with the previous line that does.

However if you have multiple multiline patterns you need to define, then it gets a tonne harder.

---

<div class="post-metadata">

**Author:** ![amir\_Bialek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/amir_bialek/32/109973_2.png) [@amir\_Bialek](https://discuss.elastic.co/u/amir_Bialek)\
**Post date:** [September 21, 2022, 4:58am UTC](https://discuss.elastic.co/t/how-to-define-multiline-in-filebeat-inputs-base-on-image/314780/3 "2022-09-21T04:58:31Z")

</div>

> [@warkolm](#):
>
> **oesn't** detect the start of your pattern. That means you can define the pattern and it'll skip individual entries. [The docs](https://www.elastic.co/guide/en/beats/filebeat/current/multiline-examples.html#multiline) mention this;
> 
> > Filebeat takes all the line

Hey, the problem is that I also have apps which send logs as single line that does not start in the same pattern as the apps that send multiline.

For example app A will send regular one line log:

```auto
action started, log level 5, connected

```

and app B will send multiline log:

```auto
2016-10-14 20:31:07,447 INFO [ACTIVE] ExecuteThread: '5' for queue: 'weblogic.kernel.Default (self-tuning)' ...

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 19, 2022, 6:59am UTC](https://discuss.elastic.co/t/how-to-define-multiline-in-filebeat-inputs-base-on-image/314780/4 "2022-10-19T06:59:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
