Multiline Match


(Matthew Iverson) #1

So I am trying to get multiline to work and am doing something stupid. Anyone see anything inherently wrong?

- type: log
  paths:
- "/var/log/elasticsearch/elasticsearch.log"
  tags: [ "elasticsearch" ]
  multiline.pattern: '^[[:space:]]+(at|\.{3})\b|^Caused by:'
  multiline.negate: false
  multiline.match: after

(Matthew Iverson) #2

When I got to Kibana and search, it is showing each line as a different item. This is whatever the standard log format for ES is


(Noémi Ványi) #3

Could you provide an example log?
Also, have you tried using the elasticsearch module provided by Filebeat: https://www.elastic.co/guide/en/beats/filebeat/6.4/filebeat-module-elasticsearch.html?


(system) #4

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.