# Multiline isn't working

**URL:** <https://discuss.elastic.co/t/multiline-isnt-working/48172>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [April 22, 2016, 1:06pm UTC](https://discuss.elastic.co/t/multiline-isnt-working/48172 "2016-04-22T13:06:32Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![jervdv](https://avatars.discourse-cdn.com/v4/letter/j/ed655f/32.png) [@jervdv](https://discuss.elastic.co/u/jervdv)\
**Post date:** [April 22, 2016, 1:06pm UTC](https://discuss.elastic.co/t/multiline-isnt-working/48172/1 "2016-04-22T13:06:32Z")

</div>

I honestly have no idea why my multiline isn't working and here is a sample of my multiline config

```
multiline:
    pattern: ^INFO \| jvm 1 \| main \| [0-9]{4}\/[0-9]{2}\/[0-9]{2} [0-9]{2}:[0-9]{2}:[0-9]{2}.[0-9]{3} \| [0-9]{2}:[0-9]{2}:[0-9]{2},[0-9]{3}
    negate: true
    match: after

```

Here is a sample data of my log

```
INFO | jvm 1 | main | 2016/03/01 09:00:14.258 | 09:00:14,190 [clearCacheJob(node2)::de.foo.platform.servicelayer.internal.jalo.ServicelayerJob] ERROR [Job] Could not start own session due to Session attribute for cronjob 'clearCacheJob(node2)' were null! [user:null, currency:8796093087777->EUR, language:8796093186080->nl
INFO | jvm 1 | main | 2016/03/01 09:00:14.258 | de.foo.platform.jalo.ConsistencyCheckException: Session attribute for cronjob 'clearCacheJob(node2)' were null! [user:null, currency:8796093087777->EUR, language:8796093186080->nl[HY-0]
INFO | jvm 1 | main | 2016/03/01 09:00:14.258 | at de.foo.platform.cronjob.jalo.Job.startOwnSession(Job.java:1138)
INFO | jvm 1 | main | 2016/03/01 09:00:14.258 | at de.foo.platform.cronjob.jalo.Job.performImpl(Job.java:762)
INFO | jvm 1 | main | 2016/03/01 09:00:14.258 | at de.foo.platform.cronjob.jalo.Job.access$1(Job.java:752)
INFO | jvm 1 | main | 2016/03/01 09:00:14.258 | at de.foo.platform.cronjob.jalo.Job$JobRunable.run(Job.java:657)
INFO | jvm 1 | main | 2016/03/01 09:00:14.258 | at de.foo.platform.util.threadpool.PoolableThread.run(PoolableThread.java:131)
INFO | jvm 1 | main | 2016/03/01 09:00:14.258 | Caused by: java.lang.IllegalStateException: Session attribute for cronjob 'clearCacheJob(node2)' were null! [user:null, currency:8796093087777->EUR, language:8796093186080->nl
INFO | jvm 1 | main | 2016/03/01 09:00:14.258 | at de.foo.platform.cronjob.jalo.CronJob.createSessionForCronJob(CronJob.java:1941)
INFO | jvm 1 | main | 2016/03/01 09:00:14.258 | at de.foo.platform.cronjob.jalo.Job.startOwnSession(Job.java:1134)
INFO | jvm 1 | main | 2016/03/01 09:00:14.258 | ... 4 more
INFO | jvm 1 | main | 2016/03/01 09:00:14.259 | 
INFO | jvm 1 | main | 2016/03/01 09:53:55.650 | 09:53:55,601 [hybrisHTTP27] WARN [UrlUtil] Unable to determine top level domain. Hostname is: testp1.piwo.pila.pl

```

He should make one log event like this:

```
    INFO | jvm 1 | main | 2016/03/01 09:00:14.258 | 09:00:14,190 [clearCacheJob(node2)::de.foo.platform.servicelayer.internal.jalo.ServicelayerJob] ERROR [Job] Could not start own session due to Session attribute for cronjob 'clearCacheJob(node2)' were null! [user:null, currency:8796093087777->EUR, language:8796093186080->nl
    INFO | jvm 1 | main | 2016/03/01 09:00:14.258 | de.foo.platform.jalo.ConsistencyCheckException: Session attribute for cronjob 'clearCacheJob(node2)' were null! [user:null, currency:8796093087777->EUR, language:8796093186080->nl[HY-0]
    INFO | jvm 1 | main | 2016/03/01 09:00:14.258 | at de.foo.platform.cronjob.jalo.Job.startOwnSession(Job.java:1138)
    INFO | jvm 1 | main | 2016/03/01 09:00:14.258 | at de.foo.platform.cronjob.jalo.Job.performImpl(Job.java:762)
    INFO | jvm 1 | main | 2016/03/01 09:00:14.258 | at de.foo.platform.cronjob.jalo.Job.access$1(Job.java:752)
    INFO | jvm 1 | main | 2016/03/01 09:00:14.258 | at de.foo.platform.cronjob.jalo.Job$JobRunable.run(Job.java:657)
    INFO | jvm 1 | main | 2016/03/01 09:00:14.258 | at de.foo.platform.util.threadpool.PoolableThread.run(PoolableThread.java:131)
    INFO | jvm 1 | main | 2016/03/01 09:00:14.258 | Caused by: java.lang.IllegalStateException: Session attribute for cronjob 'clearCacheJob(node2)' were null! [user:null, currency:8796093087777->EUR, language:8796093186080->nl
    INFO | jvm 1 | main | 2016/03/01 09:00:14.258 | at de.foo.platform.cronjob.jalo.CronJob.createSessionForCronJob(CronJob.java:1941)
    INFO | jvm 1 | main | 2016/03/01 09:00:14.258 | at de.foo.platform.cronjob.jalo.Job.startOwnSession(Job.java:1134)
    INFO | jvm 1 | main | 2016/03/01 09:00:14.258 | ... 4 more
    INFO | jvm 1 | main | 2016/03/01 09:00:14.259 |
```

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [April 25, 2016, 1:07pm UTC](https://discuss.elastic.co/t/multiline-isnt-working/48172/2 "2016-04-25T13:07:08Z")

</div>

sure it should become one log event? the timestamp of last line looks pretty much off.

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [April 25, 2016, 1:19pm UTC](https://discuss.elastic.co/t/multiline-isnt-working/48172/3 "2016-04-25T13:19:12Z")

</div>

This pattern `'^(.*\|){4} (Caused by: |.*[a-zA-Z0-9\.]+Exception|[[:space:]]|$)'` seems to work ([test out here](http://play.golang.org/p/rbMBXQv1Xi)). The pattern skips the first 4 columns and checks a line starting with `Cause by:`, contains `xxxxxException`, begins with another whitespace (`[[:space:]]` pattern) or is empty line (`$` operator).

When using yaml it's a good idea to put regular expression within single quotes `'`.

---

<div class="post-metadata">

**Author:** ![jervdv](https://avatars.discourse-cdn.com/v4/letter/j/ed655f/32.png) [@jervdv](https://discuss.elastic.co/u/jervdv)\
**Post date:** [May 3, 2016, 7:38am UTC](https://discuss.elastic.co/t/multiline-isnt-working/48172/6 "2016-05-03T07:38:58Z")

</div>

The problem is this is just one example of a possible output of the stacktrace it can have all kind of formats.  
The only thing i know is that when you have a time part after my last | a new event starts.

That is also why i made this multiline statement ^INFO | jvm 1 | main | [0-9]{4}/[0-9]{2}/[0-9]{2} [0-9]{2}:[0-9]{2}:[0-9]{2}.[0-9]{3} | [0-9]{2}:[0-9]{2}:[0-9]{2},[0-9]{3}

When i test it out in [regex101.com](http://regex101.com) everything goes perfect.  
So i think it has to do something with the parsing and/or the escape characters?

---

<div class="post-metadata">

**Author:** ![jervdv](https://avatars.discourse-cdn.com/v4/letter/j/ed655f/32.png) [@jervdv](https://discuss.elastic.co/u/jervdv)\
**Post date:** [May 3, 2016, 9:30am UTC](https://discuss.elastic.co/t/multiline-isnt-working/48172/7 "2016-05-03T09:30:01Z")

</div>

Here is my config:

```
    filebeat:
      prospectors:
        -
          paths:
            - /var/log/app_console2.log

      input_type: log

      document_type: appConsole

  registry_file: /var/lib/filebeat/registry

multiline:
    pattern: ^INFO \| jvm 1 \| main \| [0-9]{4}\/[0-9]{2}\/[0-9]{2} [0-9]{2}:[0-9]{2}:[0-9]{2}.[0-9]{3} \| [0-9]{2}:[0-9]{2}:[0-9]{2},[0-9]{3}
    negate: true
    match: after

output:
  logstash:
    hosts: ["52.49.117.253:5044"]
    bulk_max_size: 1024

    tls:
      certificate_authorities: ["/etc/pki/tls/certs/logstash-forwarder.crt"]

shipper:

logging:
  files:
    rotateeverybytes: 10485760 # = 10MB

```

Is there something wrong with the config formatting because when i use ^. as multiline pattern it doesn't even make it into one log event.

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [May 3, 2016, 11:53am UTC](https://discuss.elastic.co/t/multiline-isnt-working/48172/8 "2016-05-03T11:53:08Z")

</div>

1. when using regexes in yaml prefer to put these within single quotes `'` . YAML has 5 different kinda of string-formats with different escaping rules. single quotes is most safest option I think. Due to not having single quote yaml parser will likely remove escape characters `\` from input such that you end up with big or filter.

2. [regex101.com](http://regex101.com) only has a few regex engines. There are big/small difference between different engines. The engine used by golang is based on re2. Try [this tester](http://www.regexplanet.com/advanced/golang/index.html) and mark the 'POSIX ERE' checkbox.

3. 

> [@jervdv](#):
>
> The only thing i know is that when you have a time part after my last | a new event starts.

Oh, I missed that. This [should "simplify' the regex](https://play.golang.org/p/ZmPMvV5KPt).  
Your [pattern with variable spacing becomes](https://play.golang.org/p/dawp_fTLB_).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 9:52pm UTC](https://discuss.elastic.co/t/multiline-isnt-working/48172/9 "2017-07-05T21:52:29Z")

</div>


