# How to use json logs and also multiline together

**URL:** <https://discuss.elastic.co/t/how-to-use-json-logs-and-also-multiline-together/258347>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [December 11, 2020, 1:04am UTC](https://discuss.elastic.co/t/how-to-use-json-logs-and-also-multiline-together/258347 "2020-12-11T01:04:36Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![user2416](https://avatars.discourse-cdn.com/v4/letter/u/97f17d/32.png) [@user2416](https://discuss.elastic.co/u/user2416)\
**Post date:** [December 11, 2020, 1:04am UTC](https://discuss.elastic.co/t/how-to-use-json-logs-and-also-multiline-together/258347/1 "2020-12-11T01:04:37Z")

</div>

Hi,

We are using multiline pattern in filebeat but we also have Json logs which doesnt match that multiline pattern. We are seeing both multiline logs and json logs but some json logs are missing and also json logs are being sent to logstash very slow. Here is my configuration

Can someone please help me understand if I am doing something wrong? And how can I get both multiline matching logs and Json format logs.

```auto
 - type: log
      paths:
        - /var/lib/docker/containers/*/*.log
      json.message_key: log
      json.keys_under_root: true
      multiline.pattern: '^\d{4}-\d{2}-\d{2}\s\d{2}:\d{2}:\d{2}.\d{3}\s'
      multiline.negate: true
      multiline.match: after

```

sample logs  
Json

```auto
{"log":"{\"level\":30,\"time\":1607639208698,\"service\":\"service\",\"platform\":{\"type\":\"mobile\",\"os\":\"ios\"},\"responseMs\":124,\"hasErrors\":false}}\n","stream":"stdout","time":"2020-12-10T22:26:48.698983505Z"}

```

Multiline matching logs

```auto
{"log":"2020-12-11 01:02:13.182 INFO 1 --- log message"}}\n","stream":"stdout","time":"2020-12-11T01:02:13.182699685Z"}

```

---

<div class="post-metadata">

**Author:** ![mtojek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mtojek/32/63863_2.png) [@mtojek](https://discuss.elastic.co/u/mtojek)\
**Post date:** [December 14, 2020, 10:00am UTC](https://discuss.elastic.co/t/how-to-use-json-logs-and-also-multiline-together/258347/2 "2020-12-14T10:00:54Z")

</div>

Did you try to configure two separate inputs for different kind of logs? One for JSON logs, one for basic multiline?

---

<div class="post-metadata">

**Author:** ![user2416](https://avatars.discourse-cdn.com/v4/letter/u/97f17d/32.png) [@user2416](https://discuss.elastic.co/u/user2416)\
**Post date:** [December 16, 2020, 1:35am UTC](https://discuss.elastic.co/t/how-to-use-json-logs-and-also-multiline-together/258347/3 "2020-12-16T01:35:37Z")

</div>

@mtojek Logs for each pod are written to **/var/lib/docker/containers** location on the Kubernetes node, so we cannot have separate inputs for these 2 types of logs. Is there a way I can specify in filebeat that if pod.labels match "apptype1" use multiline and if pod.labels match "apptype2" use json?

---

<div class="post-metadata">

**Author:** ![mtojek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mtojek/32/63863_2.png) [@mtojek](https://discuss.elastic.co/u/mtojek)\
**Post date:** [December 16, 2020, 8:33am UTC](https://discuss.elastic.co/t/how-to-use-json-logs-and-also-multiline-together/258347/4 "2020-12-16T08:33:03Z")

</div>

With autodiscover you can experiment with conditions: [https://www.elastic.co/guide/en/beats/filebeat/current/configuration-autodiscover.html](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-autodiscover.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 13, 2021, 10:33am UTC](https://discuss.elastic.co/t/how-to-use-json-logs-and-also-multiline-together/258347/5 "2021-01-13T10:33:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
