# Logs with lime breaks not working with multiline

**URL:** <https://discuss.elastic.co/t/logs-with-lime-breaks-not-working-with-multiline/87937>\
**Category:** Beats\
**Created:** [June 1, 2017, 3:29pm UTC](https://discuss.elastic.co/t/logs-with-lime-breaks-not-working-with-multiline/87937 "2017-06-01T15:29:00Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![amruthapbhat](https://avatars.discourse-cdn.com/v4/letter/a/8491ac/32.png) [@amruthapbhat](https://discuss.elastic.co/u/amruthapbhat)\
**Post date:** [June 1, 2017, 3:29pm UTC](https://discuss.elastic.co/t/logs-with-lime-breaks-not-working-with-multiline/87937/1 "2017-06-01T15:29:01Z")

</div>

I have a file in the below format  
Ex:

```auto
This is the first line.

This is the second line.

```

I am using no pattern since I want all the lines in the text to send to Logstash which is around 2000 lines.

If the file is in the below format it works.  
Ex:

```auto
This is the first line.
This is the second line.

```

If the file is in the above format multiline works.

Could you please help me out with this.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [June 2, 2017, 1:37am UTC](https://discuss.elastic.co/t/logs-with-lime-breaks-not-working-with-multiline/87937/2 "2017-06-02T01:37:59Z")

</div>

Please provide the Filebeat prospector config that are you using.

---

<div class="post-metadata">

**Author:** ![amruthapbhat](https://avatars.discourse-cdn.com/v4/letter/a/8491ac/32.png) [@amruthapbhat](https://discuss.elastic.co/u/amruthapbhat)\
**Post date:** [June 2, 2017, 3:08am UTC](https://discuss.elastic.co/t/logs-with-lime-breaks-not-working-with-multiline/87937/3 "2017-06-02T03:08:04Z")

</div>

```auto
filebeat:
  prospectors:

    -
      paths:
        - /home/ubuntu/containers.d/*/*.log

      input_type: log

      document_type: syslog

      multiline:
        match: after
        max_lines: 2000

```

---

<div class="post-metadata">

**Author:** ![amruthapbhat](https://avatars.discourse-cdn.com/v4/letter/a/8491ac/32.png) [@amruthapbhat](https://discuss.elastic.co/u/amruthapbhat)\
**Post date:** [June 6, 2017, 4:10am UTC](https://discuss.elastic.co/t/logs-with-lime-breaks-not-working-with-multiline/87937/4 "2017-06-06T04:10:04Z")

</div>

Hi @andrewkroh,

Do you have any update on the above?

---

<div class="post-metadata">

**Author:** ![exekias](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/exekias/32/28718_2.png) [@exekias](https://discuss.elastic.co/u/exekias)\
**Post date:** [June 6, 2017, 9:54am UTC](https://discuss.elastic.co/t/logs-with-lime-breaks-not-working-with-multiline/87937/5 "2017-06-06T09:54:44Z")

</div>

Please don't open 2 threads for the same issue 🙂

> [@Filebeat multiline with line breaks](https://discuss.elastic.co/t/filebeat-multiline-with-line-breaks/88105/8):
>
> I think you need to set a multiline pattern like this: multiline.pattern: '.'

---

<div class="post-metadata">

**Author:** ![amruthapbhat](https://avatars.discourse-cdn.com/v4/letter/a/8491ac/32.png) [@amruthapbhat](https://discuss.elastic.co/u/amruthapbhat)\
**Post date:** [June 6, 2017, 11:00am UTC](https://discuss.elastic.co/t/logs-with-lime-breaks-not-working-with-multiline/87937/6 "2017-06-06T11:00:14Z")

</div>

@exekias Sorry for the trouble

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [June 6, 2017, 5:16pm UTC](https://discuss.elastic.co/t/logs-with-lime-breaks-not-working-with-multiline/87937/7 "2017-06-06T17:16:10Z")

</div>


