# Multi Line Pattern

**URL:** <https://discuss.elastic.co/t/multi-line-pattern/270976>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [April 22, 2021, 2:51pm UTC](https://discuss.elastic.co/t/multi-line-pattern/270976 "2021-04-22T14:51:01Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Anthony\_Azzopardi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anthony_azzopardi/32/87506_2.png) [@Anthony\_Azzopardi](https://discuss.elastic.co/u/Anthony_Azzopardi)\
**Post date:** [April 22, 2021, 2:51pm UTC](https://discuss.elastic.co/t/multi-line-pattern/270976/1 "2021-04-22T14:51:01Z")

</div>

I am currently having a hard time trying to parse a customized log to logstash using filebeat. My servers are windows servers, using the latest version of filebeat 7.0.12.

## the sample log

## Received XML Message:

SECURITYLOGINBATCH list4\<USER\_NAME\>USERNAME\</USER\_NAME\>PASSWORD\<ZONE\_ID\>1\</ZONE\_ID\>NoYes

## 20210422 05:00:06:351 - [INFO] 'SECURITY / LOGIN' Received from '' on 127.0.0.1

20210422 05:00:06:429 - [INFO] TEXT...  
20210422 05:00:06:445 - [INFO] TEXT...  
20210422 05:00:06:445 - [INFO] TEXT...  
20210422 05:00:06:445 - [INFO] TEXT...  
20210422 05:00:06:445 - [INFO] TEXT...

## Sent XML Message:

SecurityLoginSuccess\<SESSION\_ID\>0\</SESSION\_ID\>\<SERVER\_VERSION\>4\</SERVER\_VERSION\>\<SERVER\_EDITION\>Enterprise\</SERVER\_EDITION\>\<PASSWORD\_EXPIRED\>No\</PASSWORD\_EXPIRED\>\<LIST\_SET\_ID/\>\<DEFAULT\_RANK/\>\<DEFAULT\_DETECT\_COUNTRY/\>\<DEFAULT\_DETECT\_VESSEL/\>\<USER\_ZONE\_ID\>1\</USER\_ZONE\_ID\>\<USER\_ZONE\_NAME/\>\<USER\_ID\>999\</USER\_ID\>\<PROFILES\_COUNT\>1\</PROFILES\_COUNT\>\<PROFILE\_ID\>999\</PROFILE\_ID\>\<PROFILE\_NAME\>WC\</PROFILE\_NAME\>\<GROUPS\_COUNT\>1\</GROUPS\_COUNT\>\<GROUP\_ID\>999\</GROUP\_ID\>\<GROUP\_NAME\>NAME\</GROUP\_NAME\>

Example of what the log looks like formatted on server

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/9/290c8407e77bf620493b5e4ae8cb2d5f9b4b2367.png)

I am using the below to try and grab the whole log, which is not currently working.

multiline.pattern: '(?im)^Received XML Message:'  
multiline.negate: true  
multiline.match: after  
multiline.flush\_pattern: '(?im)^Sent XML Message:\r?\n\<XML.\*'

Any idea how i can manage to parse the full message please?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 20, 2021, 4:51pm UTC](https://discuss.elastic.co/t/multi-line-pattern/270976/2 "2021-05-20T16:51:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
