I need to parse a multiline event and, as suggested in the docs, I'm leaving to Filebeat the handling of the multiline:
filebeat.prospectors: - type: log paths: - /path/to/logfiletoparse.log multiline: pattern: '^Multiline event header$' negate: 'false' match: 'after'
Now, according to this config, I'd expect to see a multiline
message in Kibana. Instead, the parsed logfile is still split in multiple single-line messages. Which input/filter/output config do I need to set in Logstash to get a multiline message?