# How to define multiline.pattern for complex pattern

**URL:** <https://discuss.elastic.co/t/how-to-define-multiline-pattern-for-complex-pattern/68924>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [December 13, 2016, 6:38pm UTC](https://discuss.elastic.co/t/how-to-define-multiline-pattern-for-complex-pattern/68924 "2016-12-13T18:38:42Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![ssasporta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ssasporta/32/13695_2.png) [@ssasporta](https://discuss.elastic.co/u/ssasporta)\
**Post date:** [December 13, 2016, 6:38pm UTC](https://discuss.elastic.co/t/how-to-define-multiline-pattern-for-complex-pattern/68924/1 "2016-12-13T18:38:42Z")

</div>

I need to define the multiline.pattern field in my prospectors, instead of doing it in the logstash filter.  
The first pattern looks like that:  
`<Feb 24, 2016 4:30:07 PM IST>`  
The second pattern looks like that:  
`<<ERROR>> [Mar 01 10:05:16]`  
Before, In Logstash, I was using customized patterns.

For the first one:  
`pattern => "^\<%{WEBLOGICTIMESTAMP} "` where in my patter file I define : `WEBLOGICTIMESTAMP %{MONTH} %{MONTHDAY}, %{YEAR} %{TIME} %{DL}`

For the second one:`pattern => "^\<\<%{LOGLEVEL}\>\> "`

Thanks  
Sharon.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [December 13, 2016, 7:36pm UTC](https://discuss.elastic.co/t/how-to-define-multiline-pattern-for-complex-pattern/68924/2 "2016-12-13T19:36:37Z")

</div>

What do the intermediate lines that you want to merge look like? Can you show a sample section of the file?

---

<div class="post-metadata">

**Author:** ![ssasporta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ssasporta/32/13695_2.png) [@ssasporta](https://discuss.elastic.co/u/ssasporta)\
**Post date:** [December 13, 2016, 7:55pm UTC](https://discuss.elastic.co/t/how-to-define-multiline-pattern-for-complex-pattern/68924/3 "2016-12-13T19:55:04Z")

</div>

This is line from one log:

```
    <Feb 28, 2016 9:41:57 AM IST> <Error> <HTTP> <BEA-101020> <[ServletContext@836526773[app:ABPServer_abp.ear module:c3att path:null spec-version:3.0]] Servlet failed with an Exception
    java.lang.NullPointerException
            at jsp_servlet._rpl.__x1434944766_0_0.printInfoParam(__x1434944766_0_0.java:305)
            at jsp_servlet._rpl.__x1434944766_0_0._jspService(__x1434944766_0_0.java:610)
            at weblogic.servlet.jsp.JspBase.service(JspBase.java:35)
            at weblogic.servlet.internal.StubSecurityHelper$ServletServiceAction.run(StubSecurityHelper.java:280)
            at weblogic.servlet.internal.StubSecurityHelper$ServletServiceAction.run(StubSecurityHelper.java:254)
            Truncated. see log file for complete stacktrace
    >

```

This is line from second log:

`<<ERROR>> [Feb 29 12:51:36] [[ACTIVE] ExecuteThread: '5' for queue: 'weblogic.kernel.Default (self-tuning)'] [CM] <PayChannelServicesBean.l3UpdatePcnBalanceExpirationIndicator> encountered an exception. This bean uses Container-Managed transactions. Hence, this flow will NOT be retried. Last retry count = <0 out of 0>`

Thanks  
Sharon

---

<div class="post-metadata">

**Author:** ![hartfordfive](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hartfordfive/32/44794_2.png) [@hartfordfive](https://discuss.elastic.co/u/hartfordfive)\
**Post date:** [December 13, 2016, 8:05pm UTC](https://discuss.elastic.co/t/how-to-define-multiline-pattern-for-complex-pattern/68924/4 "2016-12-13T20:05:31Z")

</div>

Just on a side note, if your looking to test your multi-line patterns, you can use the [filebeat-multiline-tester](https://github.com/hartfordfive/filebeat-multiline-tester) tool. I haven't had much feedback on it yet, although it's been useful for me a bunch of times to test various patterns for filebeat configs.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [December 13, 2016, 8:07pm UTC](https://discuss.elastic.co/t/how-to-define-multiline-pattern-for-complex-pattern/68924/5 "2016-12-13T20:07:18Z")

</div>

If the patterns are always in separate files, can you not just simplify it by defining multiple prospectors?

---

<div class="post-metadata">

**Author:** ![ssasporta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ssasporta/32/13695_2.png) [@ssasporta](https://discuss.elastic.co/u/ssasporta)\
**Post date:** [December 13, 2016, 8:13pm UTC](https://discuss.elastic.co/t/how-to-define-multiline-pattern-for-complex-pattern/68924/6 "2016-12-13T20:13:38Z")

</div>

yes, sure, I define two different prospector and I define multiline.pattern per each prospector.

The issue is to define the right multiline.pattern.

I was thinking about:

`multiline.pattern: '^[[:graph:]][[:alpha:]][[:space:]][[:digit:]]{2}[[:graph:]][[:space:]][[:digit:]]{4}[[:space:]][[:digit:]]{2}:[[:digit:]]{2}:[[:digit:]]{2}'`

and

```
multiline.pattern: '^[[:graph:]][[:alpha:]][[:graph:]]'
       multiline.negate: true

```

accordingly

---

<div class="post-metadata">

**Author:** ![ssasporta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ssasporta/32/13695_2.png) [@ssasporta](https://discuss.elastic.co/u/ssasporta)\
**Post date:** [December 13, 2016, 8:24pm UTC](https://discuss.elastic.co/t/how-to-define-multiline-pattern-for-complex-pattern/68924/7 "2016-12-13T20:24:26Z")

</div>

It is not clear to me how to install and run the tester.

I download and put the directory on my unix.

What now?

Thanks  
Sharon.

---

<div class="post-metadata">

**Author:** ![ssasporta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ssasporta/32/13695_2.png) [@ssasporta](https://discuss.elastic.co/u/ssasporta)\
**Post date:** [December 14, 2016, 11:02am UTC](https://discuss.elastic.co/t/how-to-define-multiline-pattern-for-complex-pattern/68924/8 "2016-12-14T11:02:15Z")

</div>

still waiting for help here, how to define the pattern. Is what I did, is on the right direction? Should it be simpler?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [December 15, 2016, 6:06am UTC](https://discuss.elastic.co/t/how-to-define-multiline-pattern-for-complex-pattern/68924/9 "2016-12-15T06:06:55Z")

</div>

Do the files only contain events with these patterns or are there also events that are not multiline? It would help if you could provide a sample from each file type, e.g in a gist.

---

<div class="post-metadata">

**Author:** ![ssasporta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ssasporta/32/13695_2.png) [@ssasporta](https://discuss.elastic.co/u/ssasporta)\
**Post date:** [December 15, 2016, 8:12am UTC](https://discuss.elastic.co/t/how-to-define-multiline-pattern-for-complex-pattern/68924/10 "2016-12-15T08:12:16Z")

</div>

Wow. Great. I will load some sample to the my github and send you the link.

Thanks,  
Sharon.

---

<div class="post-metadata">

**Author:** ![ssasporta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ssasporta/32/13695_2.png) [@ssasporta](https://discuss.elastic.co/u/ssasporta)\
**Post date:** [December 15, 2016, 9:41am UTC](https://discuss.elastic.co/t/how-to-define-multiline-pattern-for-complex-pattern/68924/11 "2016-12-15T09:41:58Z")

</div>

Here are the log files examples:

[https://gist.github.com/ssasporta/8776da18c72fbd23f907154e3bb83b54.js](https://gist.github.com/ssasporta/8776da18c72fbd23f907154e3bb83b54.js)

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [December 15, 2016, 9:46am UTC](https://discuss.elastic.co/t/how-to-define-multiline-pattern-for-complex-pattern/68924/12 "2016-12-15T09:46:50Z")

</div>

Something looks wrong with this Gist. Can you try recreating it with just text files?

---

<div class="post-metadata">

**Author:** ![ssasporta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ssasporta/32/13695_2.png) [@ssasporta](https://discuss.elastic.co/u/ssasporta)\
**Post date:** [December 15, 2016, 9:58am UTC](https://discuss.elastic.co/t/how-to-define-multiline-pattern-for-complex-pattern/68924/13 "2016-12-15T09:58:05Z")

</div>

> <https://gist.github.com/ssasporta/56ec5c1df040f545a88706f6b47c550f.js>

> <https://gist.github.com/ssasporta/8f310c07469a91cfb929634ee10724b8.js>

> <https://gist.github.com/ssasporta/554d526bcf9d8136e20307268e4bc3ca.js>

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [December 15, 2016, 10:36am UTC](https://discuss.elastic.co/t/how-to-define-multiline-pattern-for-complex-pattern/68924/14 "2016-12-15T10:36:16Z")

</div>

For the `CMServer.log` file it looks to me like every new event begins with a line starting with `<<`, so you should be able to build a pattern around this if that is the case.

For the `ABPServer.log` file it looks like every new event begins with a line starting with `####`, so you should be able to build a pattern around this if that is the case.

The `weblogic.log` file seems more complicated and I am not sure how you would like the multiline events to be assembled.

I do unfortunately not have time to write and test this myself at the moment, but hopefully these pointers will get you started.

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [December 15, 2016, 1:50pm UTC](https://discuss.elastic.co/t/how-to-define-multiline-pattern-for-complex-pattern/68924/15 "2016-12-15T13:50:36Z")

</div>

Still having problems opening the gist files.

Being lazy I just copied all content shown in this discussion and used this regex `^[#\<]`

The trick about multiline is not looking at the content, but looking at the structure and re-occuring patterns at beginning or end of lines.

We do have a playground script for users to test multiline patterns. I adapted the script to include all your logs: [https://play.golang.org/p/3Eneqg-oN5](https://play.golang.org/p/3Eneqg-oN5)

Also check out the multiline tester: [https://github.com/hartfordfive/filebeat-multiline-tester](https://github.com/hartfordfive/filebeat-multiline-tester) .  
Find executables here: [Releases](https://github.com/hartfordfive/filebeat-multiline-tester/releases)

---

<div class="post-metadata">

**Author:** ![ssasporta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ssasporta/32/13695_2.png) [@ssasporta](https://discuss.elastic.co/u/ssasporta)\
**Post date:** [December 15, 2016, 2:00pm UTC](https://discuss.elastic.co/t/how-to-define-multiline-pattern-for-complex-pattern/68924/16 "2016-12-15T14:00:19Z")

</div>

great, as I have more logs and I will have to use this playground/tester.

Anyway, are you saying that the regex `^[#\<]` fits all my various format? Should I put it in all the prospectors?

Currently the filebeat is failing to start. A log isn't even created in /var/log/filebeat. I am trying to understand what is wrong there.

If you have any direction for me, it will be perfect.

Thanks  
Sharon.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [December 16, 2016, 7:59am UTC](https://discuss.elastic.co/t/how-to-define-multiline-pattern-for-complex-pattern/68924/17 "2016-12-16T07:59:05Z")

</div>

For the starting: Can you try to run it with `-e -d "*"` and see if you get some output to the console?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [December 16, 2016, 8:16am UTC](https://discuss.elastic.co/t/how-to-define-multiline-pattern-for-complex-pattern/68924/18 "2016-12-16T08:16:31Z")

</div>

I do not think it will work for your [weblogic.log](https://gist.github.com/ssasporta/8f310c07469a91cfb929634ee10724b8) file, as you in that file seem to have lines that I suspect should be part of a multiline entry that begin with `<`. Maybe something like `^[\<][A-Z][a-z]{2}[[:space:]]`, which matches the first part of the timestamp, could work for this file, although I have not tested it.

---

<div class="post-metadata">

**Author:** ![ssasporta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ssasporta/32/13695_2.png) [@ssasporta](https://discuss.elastic.co/u/ssasporta)\
**Post date:** [December 16, 2016, 12:34pm UTC](https://discuss.elastic.co/t/how-to-define-multiline-pattern-for-complex-pattern/68924/19 "2016-12-16T12:34:39Z")

</div>

Thanks. I will test it and let you know.

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [December 16, 2016, 12:46pm UTC](https://discuss.elastic.co/t/how-to-define-multiline-pattern-for-complex-pattern/68924/20 "2016-12-16T12:46:51Z")

</div>

You are right. The weblogic one looks quite crazy. I'd definitely put weblogic.log into a separate prospector. weblogic.log always starts with `<`, plus date. You can try to be a little more strict by doing `^\<[JFMASOND][a-z]{2} \d{2},` or try something like `^\<[^\<]`. The latter pattern matches a string starting with `<` not followed by another `<`. The pattern `[^...]` negates the characters listed.

[Next page](https://discuss.elastic.co/t/how-to-define-multiline-pattern-for-complex-pattern/68924.md?page=2)
