# Issues with multiline

**URL:** <https://discuss.elastic.co/t/issues-with-multiline/93355>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [July 17, 2017, 8:15am UTC](https://discuss.elastic.co/t/issues-with-multiline/93355 "2017-07-17T08:15:17Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ron\_Sevet](https://avatars.discourse-cdn.com/v4/letter/r/76d3ee/32.png) [@Ron\_Sevet](https://discuss.elastic.co/u/Ron_Sevet)\
**Post date:** [July 17, 2017, 8:15am UTC](https://discuss.elastic.co/t/issues-with-multiline/93355/1 "2017-07-17T08:15:17Z")

</div>

Hi,

I'm trying to use multiline on filebeat, here is the config -

```auto
filebeat.prospectors:

- input_type: log
  paths:
    #- /var/log/*.log
    - c:\inetpub\logs\LogFiles\W3SVC161606440\*
  document_type: iis-il2

- input_type: log
  paths:
    - c:\AppServerLog\*\*
  document_type: webapplogstest
  exclude_lines: ["^#"]
  include_lines: ["^20"]
  multiline.pattern: '^\[[0-9]{4}-[0-9]{2}-[0-9]{2}'
  multiline.negate: true
  multiline.match: after

```

I have lines like this -

```auto
2017-07-17 03:06:29; Info; 32;Infraworks.Core.NetUtils.AppServerClient::Refresh ;"Member http://appsrv5.imlive.com:8080/ added to connection pool";
2017-07-17 03:06:29; Info; 32;Infraworks.Core.NetUtils.AppServerClient::Refresh ;"Member http://appsrv1.imlive.com:8080/ added to connection pool";
2017-07-17 03:06:29; Info; 32;Infraworks.Core.NetUtils.AppServerClient::Refresh ;"Member http://appsrv2.imlive.com:8080/ added to connection pool";
2017-07-17 03:06:29; Info; 32;Infraworks.Core.NetUtils.AppServerClient::Refresh ;"Member http://appsrv3.imlive.com:8080/ added to connection pool";
2017-07-17 03:06:29; Info; 32;Infraworks.Core.NetUtils.AppServerClient::Refresh ;"Member http://appsrv4.imlive.com:8080/ added to connection pool";

```

and the message I get is similar without seperation to singular event per line.

How may I fix this?

Thanks,

Ron

---

<div class="post-metadata">

**Author:** ![tudor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor/32/3753_2.png) [@tudor](https://discuss.elastic.co/u/tudor)\
**Post date:** [July 17, 2017, 8:37am UTC](https://discuss.elastic.co/t/issues-with-multiline/93355/2 "2017-07-17T08:37:23Z")

</div>

This seems similar to [Filebeat multiline](https://discuss.elastic.co/t/filebeat-multiline/93326). Your pattern seems to expect an extra leading `[`.

---

<div class="post-metadata">

**Author:** ![Ron\_Sevet](https://avatars.discourse-cdn.com/v4/letter/r/76d3ee/32.png) [@Ron\_Sevet](https://discuss.elastic.co/u/Ron_Sevet)\
**Post date:** [July 17, 2017, 9:21am UTC](https://discuss.elastic.co/t/issues-with-multiline/93355/3 "2017-07-17T09:21:08Z")

</div>

Hi Tudor,

Thank you for the prompt response, I tried what you suggested and I was certain it was right on the money,  
unfortunately I still get the events joined -  
2017-07-17 04:14:56; Info; 41;...ks.Core.GenericServers.HostedServer::MainThread;"Performing global refresh...";  
2017-07-17 04:14:56; Info; 41;...ks.Core.GenericServers.HostedServer::MainThread;"pluginglobalrefresh - duration 54";  
2017-07-17 04:14:56; Info; 41;...ks.Core.GenericServers.HostedServer::MainThread;"Forcing garbadge collecting... (heap size: 693786912)";  
2017-07-17 04:14:56; Info; 41;...ks.Core.GenericServers.HostedServer::MainThread;"beforemanualgc 693786912 bytes";  
2017-07-17 04:14:57; Info; 41;...ks.Core.GenericServers.HostedServer::MainThread;"Forcing garbadge collecting (step 1)";  
2017-07-17 04:14:57; Info; 41;...ks.Core.GenericServers.HostedServer::MainThread;"Forcing garbadge collecting (step 2)";  
2017-07-17 04:14:57; Info; 41;...ks.Core.GenericServers.HostedServer::MainThread;"Forcing garbadge collecting (step 3)";  
2017-07-17 04:14:57; Info; 41;...ks.Core.GenericServers.HostedServer::MainThread;"aftermanualgc - duration 319, 517915152 bytes, 175871760 delta";  
2017-07-17 04:14:57; Info; 41;...ks.Core.GenericServers.HostedServer::MainThread;"#### Server Stats #####: Hits per second: 3.10572021626432";

This is one message in ES.

Any other ideas?

Thanks,

Ron

---

<div class="post-metadata">

**Author:** ![tudor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor/32/3753_2.png) [@tudor](https://discuss.elastic.co/u/tudor)\
**Post date:** [July 17, 2017, 10:28am UTC](https://discuss.elastic.co/t/issues-with-multiline/93355/4 "2017-07-17T10:28:14Z")

</div>

Can you post again your config file?

---

<div class="post-metadata">

**Author:** ![Ron\_Sevet](https://avatars.discourse-cdn.com/v4/letter/r/76d3ee/32.png) [@Ron\_Sevet](https://discuss.elastic.co/u/Ron_Sevet)\
**Post date:** [July 17, 2017, 10:32am UTC](https://discuss.elastic.co/t/issues-with-multiline/93355/5 "2017-07-17T10:32:54Z")

</div>

###################### Filebeat Configuration Example #########################

# This file is an example configuration file highlighting only the most common

# options. The filebeat.full.yml file from the same directory contains all the

# supported options with more comments. You can use it as a reference.

# 

# You can find the full configuration reference here:

# [https://www.elastic.co/guide/en/beats/filebeat/index.html](https://www.elastic.co/guide/en/beats/filebeat/index.html)

#=========================== Filebeat prospectors =============================

filebeat.prospectors:

# Each - is a prospector. Most options can be set at the prospector level, so

# you can use different prospectors for various configurations.

# Below are the prospector specific configurations.

- input\_type: log

- input\_type: log  
paths:

#================================ General =====================================

# The name of the shipper that publishes the network data. It can be used to group

# all the transactions sent by a single shipper in the web interface.

#name:

# The tags of the shipper are included in their own field with each

# transaction published.

#tags: ["service-X", "web-tier"]

# Optional fields that you can specify to add additional information to the

# output.

#fields:

# env: staging

#================================ Outputs =====================================

# Configure what outputs to use when sending the data collected by the beat.

# Multiple outputs may be used.

#-------------------------- Elasticsearch output ------------------------------  
#output.elasticsearch:

# Array of hosts to connect to.

#hosts: ["localhost:9200"]

# Optional protocol and basic auth credentials.

#protocol: "https"  
#username: "elastic"  
#password: "changeme"

#----------------------------- Logstash output --------------------------------  
output.logstash:

# The Logstash hosts

hosts: ["10.100.13.191:5044"]

# Optional SSL. By default is off.

# List of root certificates for HTTPS server verifications

#ssl.certificate\_authorities: ["/etc/pki/root/ca.pem"]

# Certificate for SSL client authentication

#ssl.certificate: "/etc/pki/client/cert.pem"

# Client Certificate Key

#ssl.key: "/etc/pki/client/cert.key"

#================================ Logging =====================================

# Sets log level. The default log level is info.

# Available log levels are: critical, error, warning, info, debug

#logging.level: debug

# At debug level, you can selectively enable logging only for some components.

# To enable all selectors use ["\*"]. Examples of other selectors are "beat",

# "publish", "service".

#logging.selectors: ["\*"]

---

<div class="post-metadata">

**Author:** ![Ron\_Sevet](https://avatars.discourse-cdn.com/v4/letter/r/76d3ee/32.png) [@Ron\_Sevet](https://discuss.elastic.co/u/Ron_Sevet)\
**Post date:** [July 20, 2017, 6:23am UTC](https://discuss.elastic.co/t/issues-with-multiline/93355/6 "2017-07-20T06:23:51Z")

</div>

Can someone please help me out here?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 17, 2017, 6:24am UTC](https://discuss.elastic.co/t/issues-with-multiline/93355/7 "2017-08-17T06:24:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
