# Multi Line Pattern

**URL:** <https://discuss.elastic.co/t/multi-line-pattern/270972>\
**Category:** Beats\
**Created:** [April 22, 2021, 2:09pm UTC](https://discuss.elastic.co/t/multi-line-pattern/270972 "2021-04-22T14:09:44Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Anthony\_Azzopardi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anthony_azzopardi/32/87506_2.png) [@Anthony\_Azzopardi](https://discuss.elastic.co/u/Anthony_Azzopardi)\
**Post date:** [April 22, 2021, 2:09pm UTC](https://discuss.elastic.co/t/multi-line-pattern/270972/1 "2021-04-22T14:09:44Z")

</div>

Hello everyone,

I am currently having a hard time trying to parse a customized log to logstash using filebeat. My servers are windows servers, using the latest version of filebeat 7.0.12.

## the sample log

## Received XML Message: SECURITYLOGINBATCH list4\<USER\_NAME\>USERNAME\</USER\_NAME\>PASSWORD\<ZONE\_ID\>1\</ZONE\_ID\>NoYes

## 20210422 05:00:06:351 - [INFO] 'SECURITY / LOGIN' Received from '' on 127.0.0.1 20210422 05:00:06:429 - [INFO] TEXT... 20210422 05:00:06:445 - [INFO] TEXT... 20210422 05:00:06:445 - [INFO] TEXT... 20210422 05:00:06:445 - [INFO] TEXT... 20210422 05:00:06:445 - [INFO] TEXT...

## Sent XML Message: SecurityLoginSuccess\<SESSION\_ID\>0\</SESSION\_ID\>\<SERVER\_VERSION\>4\</SERVER\_VERSION\>\<SERVER\_EDITION\>Enterprise\</SERVER\_EDITION\>\<PASSWORD\_EXPIRED\>No\</PASSWORD\_EXPIRED\>\<LIST\_SET\_ID/\>\<DEFAULT\_RANK/\>\<DEFAULT\_DETECT\_COUNTRY/\>\<DEFAULT\_DETECT\_VESSEL/\>\<USER\_ZONE\_ID\>1\</USER\_ZONE\_ID\>\<USER\_ZONE\_NAME/\>\<USER\_ID\>999\</USER\_ID\>\<PROFILES\_COUNT\>1\</PROFILES\_COUNT\>\<PROFILE\_ID\>999\</PROFILE\_ID\>\<PROFILE\_NAME\>WC\</PROFILE\_NAME\>\<GROUPS\_COUNT\>1\</GROUPS\_COUNT\>\<GROUP\_ID\>999\</GROUP\_ID\>\<GROUP\_NAME\>NAME\</GROUP\_NAME\>

Example of what the log looks like formatted on server

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/9/89d6549bb9d8eb031fe0957322c55838116672a7.png)

I am using the below to try and grab the whole log, which is not currently working.

multiline.pattern: '(?im)^Received XML Message:'  
multiline.negate: true  
multiline.match: after  
multiline.flush\_pattern: '(?im)^Sent XML Message:\r?\n\<XML.\*'

Any idea how i can manage to parse the full message please?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 22, 2021, 2:46pm UTC](https://discuss.elastic.co/t/multi-line-pattern/270972/2 "2021-04-22T14:46:08Z")

</div>

If you have a question about filebeat you would be better off asking in the beats forum rather than the logstash forum.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 20, 2021, 2:46pm UTC](https://discuss.elastic.co/t/multi-line-pattern/270972/3 "2021-05-20T14:46:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
