MultiLine Message handling


(VISHNU) #1

Hi,
Its already quoted in the logstash as follows

If you are using a Logstash input plugin that supports multiple hosts, such as the [beats input plugin](http://www.elastic.co/guide/en/logstash/6.4/plugins-inputs-beats.html), you should not use the multiline codec to handle multiline events. Doing so may result in the mixing of streams and corrupted event data. In this situation, you need to handle multiline events before sending the event data to Logstash.

I am having 200+ server with tomcat application installed in those servers. I was in a plan to push the logs using filebeat to logstash further into ES and Kibana.
Thus as mentioned above , for my scenario, how will I manage the multiline messages in my client machines?
Whether I need to use Logstash in every client machines for the log management or is there any other way to handle this scenario?

Request to advise!
Thanks


(VISHNU) #2

Any advise!


(Tek Chand) #3

@VISHNU, You need to handle it at filebeat level.

You can refer the below link:

https://www.elastic.co/guide/en/beats/filebeat/current/multiline-examples.html

Thanks.


(system) #4

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.