# Multiline in filebeat

**URL:** <https://discuss.elastic.co/t/multiline-in-filebeat/107879>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [November 16, 2017, 8:12am UTC](https://discuss.elastic.co/t/multiline-in-filebeat/107879 "2017-11-16T08:12:28Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Manasa](https://avatars.discourse-cdn.com/v4/letter/m/5fc32e/32.png) [@Manasa](https://discuss.elastic.co/u/Manasa)\
**Post date:** [November 16, 2017, 8:12am UTC](https://discuss.elastic.co/t/multiline-in-filebeat/107879/1 "2017-11-16T08:12:28Z")

</div>

Multiline is clubbing unmatched lines to another event. Please let me know how I can exclude those lines. I want only the XML in the output.

Example log file

```
line1
line2
<Errors>
inside the xml1
   inside the xml1-abc
</Errors>
outsideXML1
outsideXML1-line2
<Errors>
inside the xml2
   inside the xml2-abc
</Errors>
outside the xml2

```

pattern in filebeat.yml

```
  multiline:
    pattern: '<Errors>'
    negate: true
    match: after
    flush_pattern: '</Errors>'

```

Output file

```
{"@timestamp":"2017-11-16T06:09:41.821Z","@metadata":{"beat":"filebeat","type":"doc","version":"6.0.0"},"message":"line1\nline2","source":"/opt/servers/logs/test1.log","offset":12,"prospector":{"type":"log"},"beat":{"name":"ip-10-120-212-122.ap-south-1.compute.internal","hostname":"ip-10-120-212-122.ap-south-1.compute.internal","version":"6.0.0"}}
{"@timestamp":"2017-11-16T06:09:41.821Z","@metadata":{"beat":"filebeat","type":"doc","version":"6.0.0"},"source":"/opt/servers/logs/test1.log","offset":70,"message":"\u003cErrors\u003e\ninside the xml1\n inside the xml1-abc\n\u003c/Errors\u003e","prospector":{"type":"log"},"beat":{"name":"ip-10-120-212-122.ap-south-1.compute.internal","hostname":"ip-10-120-212-122.ap-south-1.compute.internal","version":"6.0.0"}}
{"@timestamp":"2017-11-16T06:09:41.821Z","@metadata": **{"beat":"filebeat","type":"doc","version":"6.0.0"},"source":"/opt/servers/logs/test1.log","offset":100,"message":"outsideXML1\noutsideXML1-line2","prospector":{"type":"log"},"beat":{"name":"ip-10-120-212-122.ap-south-1.compute.internal","hostname":"ip-10-120-212-122.ap-south-1.compute.internal","version":"6.0.0"}}**
{"@timestamp":"2017-11-16T06:09:41.822Z","@metadata":{"beat":"filebeat","type":"doc","version":"6.0.0"},"beat":{"name":"ip-10-120-212-122.ap-south-1.compute.internal","hostname":"ip-10-120-212-122.ap-south-1.compute.internal","version":"6.0.0"},"source":"/opt/servers/logs/test1.log","offset":158,"message":"\u003cErrors\u003e\ninside the xml2\n inside the xml2-abc\n\u003c/Errors\u003e","prospector":{"type":"log"}}
{"@timestamp":"2017-11-16T06:09:41.822Z","@metadata":{"beat":"filebeat","type":"doc","version":"6.0.0"},"source":"/opt/servers/logs/test1.log","offset":176,"message":"outside the xml2\n","prospector":{"type":"log"},"beat":{"name":"ip-10-120-212-122.ap-south-1.compute.internal","hostname":"ip-10-120-212-122.ap-south-1.compute.internal","version":"6.0.0"}}

```

I want only second and fourth lines in the output.

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [November 16, 2017, 1:43pm UTC](https://discuss.elastic.co/t/multiline-in-filebeat/107879/2 "2017-11-16T13:43:38Z")

</div>

For this use-case you would need to have a start + flush pattern, such that multiline is only active after the start-pattern has been hit. The multiline as is, is always active. Feel free to file an [enhancement request](https://github.com/elastic/beats/issues).

---

<div class="post-metadata">

**Author:** ![Manasa](https://avatars.discourse-cdn.com/v4/letter/m/5fc32e/32.png) [@Manasa](https://discuss.elastic.co/u/Manasa)\
**Post date:** [November 21, 2017, 2:50am UTC](https://discuss.elastic.co/t/multiline-in-filebeat/107879/3 "2017-11-21T02:50:20Z")

</div>

Thanks for the response. I resolved it by adding i`nclude_lines = <Errors>`  
I will try start + flush as well.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 19, 2017, 2:50am UTC](https://discuss.elastic.co/t/multiline-in-filebeat/107879/4 "2017-12-19T02:50:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
