# Manage multiline

**URL:** <https://discuss.elastic.co/t/manage-multiline/104636>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [October 20, 2017, 2:57am UTC](https://discuss.elastic.co/t/manage-multiline/104636 "2017-10-20T02:57:36Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Fei\_Yao](https://avatars.discourse-cdn.com/v4/letter/f/85e7bf/32.png) [@Fei\_Yao](https://discuss.elastic.co/u/Fei_Yao)\
**Post date:** [October 20, 2017, 2:57am UTC](https://discuss.elastic.co/t/manage-multiline/104636/1 "2017-10-20T02:57:36Z")

</div>

Hi,  
I've read [https://www.elastic.co/guide/en/beats/filebeat/current/multiline-examples.html](https://www.elastic.co/guide/en/beats/filebeat/current/multiline-examples.html). But It didn't help me for the downstream [Elasticsearch Ingest Pipeline Grok Processor](https://www.elastic.co/guide/en/elasticsearch/reference/master/grok-processor.html).

The challenge I have is the following ONE log event has been broken into TWO events by Filebeat. The first one has great Grok pattern I'd like to match. But the second one doesn't have such pattern to match and it breaks the pipeline.

I wonder Filebeat team or Elasticsearch team has any solution for this? Ideally, I want Filebeat be able to 1) process multiline, which it does well, 2) make sure below is one event. Possible?

```auto
2017-10-19 22:48:08.166 ERROR 19345 --- [http-nio-8080-exec-1] com.example.demo.GlobalExceptionHandler : Unhandled exception occurred

java.lang.IllegalArgumentException: Missing parameter
	at com.example.demo.HiController.greeting(HiController.java:30) ~[classes!/:0.0.1-SNAPSHOT]
	at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method) ~[na:1.8.0_144]

```

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [October 23, 2017, 12:45pm UTC](https://discuss.elastic.co/t/manage-multiline/104636/2 "2017-10-23T12:45:16Z")

</div>

Looks like you want to apply multiline on the date pattern (e.g. `'^\d{4}-\d{2}-\d{2} \d{2}:\d{2}:\d{2}.\d{3} '`) and use negate true.

You can configure multiple grok patterns in your Ingest Node Pipeline. The grok processor will try each definition (one after another) and only fail if none matches.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 20, 2017, 12:45pm UTC](https://discuss.elastic.co/t/manage-multiline/104636/3 "2017-11-20T12:45:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
