# How to send log that has many line breaks as one entry

**URL:** <https://discuss.elastic.co/t/how-to-send-log-that-has-many-line-breaks-as-one-entry/31967>\
**Category:** Logstash\
**Created:** [October 11, 2015, 1:40pm UTC](https://discuss.elastic.co/t/how-to-send-log-that-has-many-line-breaks-as-one-entry/31967 "2015-10-11T13:40:47Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![M.Tyler](https://avatars.discourse-cdn.com/v4/letter/m/94ad74/32.png) [@M.Tyler](https://discuss.elastic.co/u/M.Tyler)\
**Post date:** [October 11, 2015, 1:40pm UTC](https://discuss.elastic.co/t/how-to-send-log-that-has-many-line-breaks-as-one-entry/31967/1 "2015-10-11T13:40:47Z")

</div>

Please let me question how to collect Windows Defender log using logstash.

Windows Defender output log such as the below sample when virus is detected.  
But the log has a lot of a line breaks in one detection log.  
So logstash send a lot of log to elasticsearch.  
Please tell me how to send the below log as one entry.

@sample

Begin Quick Scan  
Scan ID:{ECAB1DAA-924B-468D-AEB9-6FCEEBD153D1}  
Scan Source:2  
Start Time:日 10 11 2015 14:04:42  
End Time:日 10 11 2015 14:07:13  
Result Count:1  
Threat Name:Tool:Win32/EICAR\_Test\_File  
ID:17463  
Severity:5  
Number of Resources:3  
Resource Schema:file  
Resource Path:C:\Users\Administrator\Desktop\X5O!P%\_AP[4\_PZX54\_P^_7CC\_7_$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H.txt  
Extended Info:5866324352432  
Resource Schema:file  
Resource Path:C:\Users\Administrator\Desktop\3.txt  
Extended Info:5866324352432  
Resource Schema:file  
Resource Path:C:\Users\Administrator\Desktop\2.txt  
Extended Info:5866324352432  
End Scan

* * *

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 11, 2015, 4:08pm UTC](https://discuss.elastic.co/t/how-to-send-log-that-has-many-line-breaks-as-one-entry/31967/2 "2015-10-11T16:08:24Z")

</div>

Use a multline filter or multiline codec to join consecutive lines. The multiline logic would be something like "unless the line begins with 'Begin Quick Scan', join the current line with the previous line".

---

<div class="post-metadata">

**Author:** ![M.Tyler](https://avatars.discourse-cdn.com/v4/letter/m/94ad74/32.png) [@M.Tyler](https://discuss.elastic.co/u/M.Tyler)\
**Post date:** [October 16, 2015, 10:32am UTC](https://discuss.elastic.co/t/how-to-send-log-that-has-many-line-breaks-as-one-entry/31967/3 "2015-10-16T10:32:34Z")

</div>

Hi Magnusbaeck,

Thank you for your reply !!

I set logstash.conf as the below.

\*\*\*\* @ logstash.conf \*\*\*\*  
input {  
file {  
path =\> "C:/ProgramData/Microsoft/Windows Defender/Support/MPLog-\*.log"  
tags =\> "AntiVirus"  
type =\> 'WindowsDefender'  
}

}

filter {  
multiline {  
type =\> 'WindowsDefender'  
pattern =\> "Begin Quick Scan"  
what =\> "previous"  
}  
}

output {  
stdout {}  
}  
\*\*\*\* @ logstash.conf \*\*\*\*

But it seems to not be filtered.  
How should I modify logstash.conf ?

BTW, Windows Defender Log start from a line break as the below.

* * *

Begin Quick Scan  
Scan ID:{ECAB1DAA-924B-468D-AEB9-6FCEEBD153D1}  
Scan Source:2  
Start Time:日 10 11 2015 14:04:42  
End Time:日 10 11 2015 14:07:13  
Result Count:1  
Threat Name:Tool:Win32/EICAR\_Test\_File  
ID:17463  
Severity:5  
Number of Resources:3  
Resource Schema:file  
Resource Path:C:\Users\Administrator\Desktop\X5O!P%\_AP[4\_PZX54\_P^_7CC\_7_$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H.txt  
Extended Info:5866324352432  
Resource Schema:file  
Resource Path:C:\Users\Administrator\Desktop\3.txt  
Extended Info:5866324352432  
Resource Schema:file  
Resource Path:C:\Users\Administrator\Desktop\2.txt  
Extended Info:5866324352432  
End Scan

* * *

Best regards,  
Tyler

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 16, 2015, 10:42am UTC](https://discuss.elastic.co/t/how-to-send-log-that-has-many-line-breaks-as-one-entry/31967/4 "2015-10-16T10:42:14Z")

</div>

You're missing the negation in " **unless** the line begins with 'Begin Quick Scan', join the current line with the previous line". Add `negate => true` to the multiline filter.

Also, don't use `type` in the filter. That form has been deprecated for a long time and will be removed completely in Logstash 2.0. Wrap the filter in a conditional instead.

```
if [type] == "WindowsDefender" {
  multiline {
     ...
  }
}
```

---

<div class="post-metadata">

**Author:** ![M.Tyler](https://avatars.discourse-cdn.com/v4/letter/m/94ad74/32.png) [@M.Tyler](https://discuss.elastic.co/u/M.Tyler)\
**Post date:** [October 17, 2015, 11:08am UTC](https://discuss.elastic.co/t/how-to-send-log-that-has-many-line-breaks-as-one-entry/31967/5 "2015-10-17T11:08:40Z")

</div>

Thank you for your description.  
I can filter by your procedure.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:26am UTC](https://discuss.elastic.co/t/how-to-send-log-that-has-many-line-breaks-as-one-entry/31967/6 "2017-07-06T05:26:17Z")

</div>


