# Logfiles seem to be combining!

**URL:** <https://discuss.elastic.co/t/logfiles-seem-to-be-combining/45000>\
**Category:** Kibana\
**Created:** [March 21, 2016, 2:07pm UTC](https://discuss.elastic.co/t/logfiles-seem-to-be-combining/45000 "2016-03-21T14:07:19Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Pete\_Griggs](https://avatars.discourse-cdn.com/v4/letter/p/c57346/32.png) [@Pete\_Griggs](https://discuss.elastic.co/u/Pete_Griggs)\
**Post date:** [March 21, 2016, 2:07pm UTC](https://discuss.elastic.co/t/logfiles-seem-to-be-combining/45000/1 "2016-03-21T14:07:20Z")

</div>

Hello,

I have 2 inputs for log files with 2 separate types for example Internal on one and External on another.

For some reason when the data reaches Kibana it is joining them together. For example  
"85.833, 20.233, 85.833, 20.233" all in one field. Any ideas it is driving me potty!

cheers  
Pete.

---

<div class="post-metadata">

**Author:** ![michelle.foy](https://avatars.discourse-cdn.com/v4/letter/m/7c8e57/32.png) [@michelle.foy](https://discuss.elastic.co/u/michelle.foy)\
**Post date:** [March 21, 2016, 2:52pm UTC](https://discuss.elastic.co/t/logfiles-seem-to-be-combining/45000/2 "2016-03-21T14:52:48Z")

</div>

I was having that same issue - and I think it was due to using multiline in both Filebeat and Logstash. Once I removed my multiline plugins in Logstash I stopped getting those errors.

Of course, you may also be getting that error if you are accidentally adding to that field multiple times in your Logstash config.

---

<div class="post-metadata">

**Author:** ![Pete\_Griggs](https://avatars.discourse-cdn.com/v4/letter/p/c57346/32.png) [@Pete\_Griggs](https://discuss.elastic.co/u/Pete_Griggs)\
**Post date:** [March 21, 2016, 3:31pm UTC](https://discuss.elastic.co/t/logfiles-seem-to-be-combining/45000/3 "2016-03-21T15:31:32Z")

</div>

Hi Michelle,

Are you able to explain a bit more about the filebeat?

Here is my config

input {  
lumberjack {  
port =\> 5000  
type =\> "logs"  
ssl\_certificate =\> "crt"  
ssl\_key =\> "key"  
}  
}  
input {  
file {  
path =\> "to logfile"  
type =\> "snort\_external" # a type to identify those logs (will need this later)  
start\_position =\> "beginning"  
}  
}  
#Snort  
filter{  
grok {  
match =\> { "message" =\> "%{SYSLOG5424SD} ((%{DATA:snort\_rule\_mod} ))?(%{DATA:snort\_rule}) %{GREEDYDATA:snort\_msg\_v} [Classification: %{DATA:snort\_classification}] [Priority: %{INT:snort\_priority}] {%{WORD:protocol}} %{IP:src\_ip}:%{INT:src\_port} -\> %{IP:dst\_ip}:%{INT:dst\_port}" }  
add\_field =\> ["Priority", "%{snort\_priority}"]  
add\_field =\> ["Classification", "%{snort\_classification}"]  
}  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 21, 2016, 6:26pm UTC](https://discuss.elastic.co/t/logfiles-seem-to-be-combining/45000/4 "2016-03-21T18:26:42Z")

</div>

For which field are you seeing this result? What was the input line in that case?

> Are you able to explain a bit more about the filebeat?

You're not using Filebeat so that's a distraction.

> add\_field =\> ["Priority", "%{snort\_priority}"]

Why not capture the priority into the Priority field in the first place instead of capturing it into snort\_priority and copying that value into Priority?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:58pm UTC](https://discuss.elastic.co/t/logfiles-seem-to-be-combining/45000/5 "2017-07-06T13:58:26Z")

</div>


