Multiline Configuration / Java Stack Trace

(Christian Schlaefcke) #1


I just started working with docker elk and also have filebeat for some docker containers up and running (almost). One of my docker container (JIRA) is creating multiline output (mainly java exceptions / stack traces) and thanks to the excellent filebeat documentation I was able to fetch java stack traces as a single log entry.

I simply took this multiline configuration from the docs:

multiline.pattern: '^[[:space:]]+(at|\.{3})\b|^Caused by:'
multiline.negate: false
multiline.match: after

But sometimes I have exception like this one:

java.lang.IllegalArgumentException: Cannot find Screen with id '13300'.
    at com.atlassian.jira.workflow.WorkflowActionsBean.getFieldScreenForView(
    at com.atlassian.jira.workflow.AbstractJiraWorkflow.loadFieldScreenActions(
    at com.atlassian.jira.workflow.AbstractJiraWorkflow.getActionsForScreen(
    at com.atlassian.jira.web.action.admin.issuefields.screens.ViewFieldScreens.getWorkflowTransitionViews(
    at sun.reflect.GeneratedMethodAccessor1513.invoke(Unknown Source)
    ... 1 filtered
    at java.lang.reflect.Method.invoke(
    at webwork.util.InjectionUtils$DefaultInjectionImpl.invoke(
    at webwork.util.InjectionUtils.invoke(
    at webwork.util.ValueStack.findValue(
    at webwork.util.ValueStack.findValue(
    at webwork.view.taglib.WebWorkBodyTagSupport.findValue(
    at webwork.view.taglib.BasicPropertyTag.doStartTag(

And from the beginning of the line

... 1 filtered

a new event will be discovered :frowning: - somehow the multiline.pattern is not fetching it correctly even though the docs say:

a line that begins with spaces followed by the word  `at`  or  `...`

Any idea pointing me in the right direction would very much appreciated!

Best Regards,


(Christian Schlaefcke) #2

After I found the hint for testing my pattern first it is at least obvious that the current pattern is not matching the line with dots:

(Christian Schlaefcke) #3

Okay now - I´ve played around a bit with the pattern and it seems that the word boundary switch (\b) is causing problems. Even though I am not sure what exactly it was intended for - changing the pattern from:

multiline.pattern: '^[[:space:]]+(at|\.{3})\b|^Caused by:'


multiline.pattern: '^[[:space:]]+(at|\.{3})|^Caused by:'

makes my filebeat configuration work like desired :+1:

(system) #4

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.