# Multiline pattern setting for multiple loglines in XML file

**URL:** <https://discuss.elastic.co/t/multiline-pattern-setting-for-multiple-loglines-in-xml-file/183618>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 30, 2019, 9:56pm UTC](https://discuss.elastic.co/t/multiline-pattern-setting-for-multiple-loglines-in-xml-file/183618 "2019-05-30T21:56:15Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![kishorerv93](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kishorerv93/32/47194_2.png) [@kishorerv93](https://discuss.elastic.co/u/kishorerv93)\
**Post date:** [May 30, 2019, 9:56pm UTC](https://discuss.elastic.co/t/multiline-pattern-setting-for-multiple-loglines-in-xml-file/183618/1 "2019-05-30T21:56:15Z")

</div>

Hi,

Below is my xml file.

Now my question is, I was able get every line in the above xml in a each message, but i'm unable to get all the log lines in a single message.

Anyone can assist ?

Thanks

```auto
<?xml-stylesheet alternate="yes" href="./event_log.xsl" type="text/xsl"?>
<?xml-stylesheet alternate="yes" href="file://c:/drive/bin/event_log.xsl" type="text/xsl"?>
<EventLog SetMinutes="800" Id="8000" Process="Player.exe">
<Clock ClockId="CLk-21e21412414=4-1341341414141"/>
<Entry serial_no="0" mcycle="2132424124-4141" Thread="player" ThreadId="tester" Seconds="11231243241.354123" Severity="info" >Local player details - Receievd metrics
player has reached 1000 level and need to get an xp
player has reached 100 level and need to get an xp
player has reached to 70 level and need to get an xp
player has reached 1000 level and need to get an xp
player has reached 100 level and need to get an xp
player has reached to 70 level and need to get an xp
player has reached 400 level and need to get an xp
player has reached 100 level and need to get an xp
player has reached to 30 level and need to get an xp
player has reached 103 level and need to get an xp
player has reached 130 level and need to get an xp
player has reached to 70 level and need to get an xp
player has reached 1000 level and need to get an xp
player has reached 100 level and need to get an xp
player has reached to 70 level and need to get an xp
player has reached 3300 level and need to get an xp
player has reached 100 level and need to get an xp
player has reached to 70 level and need to get an xp
player has reached 1300 level and need to get an xp
player has reached 103 level and need to get an xp
player has reached 1000 level and need to get an xp
player has reached 100 level and need to get an xp
player has reached to 70 level and need to get an xp
player has reached 1000 level and need to get an xp
player has reached 100 level and need to get an xp
player has reached to 70 level and need to get an xp
player has reached 400 level and need to get an xp
player has reached 100 level and need to get an xp
player has reached to 30 level and need to get an xp
player has reached 103 level and need to get an xp
player has reached 130 level and need to get an xp
player has reached to 70 level and need to get an xp
player has reached 1000 level and need to get an xp
player has reached 100 level and need to get an xp
player has reached to 70 level and need to get an xp
player has reached 3300 level and need to get an xp
player has reached 100 level and need to get an xp
player has reached to 70 level and need to get an xp
player has reached 1300 level and need to get an xp
player has reached 103 level and need to get an xp
player has reached to 733 level and need to get an xp
</Entry>
</Eventlog>

```

```
This is how my multiline in filebeat.yml looks like

```

```auto
multiline.pattern: '^<Entry|^=[a-z]'
      multiline.negate : false
      multiline.match: after

```

My logstash.conf

```auto
input{
   beats {
       port => 5044
 }

}
filter{
    xml{
        source => message
        store_xml => true
        target => "doc"
        xpath => ["/Eventlog[@name='ThreadId']@value", "ThreadId",
                          "/Eventlog[@name='Thread']@value", "Thread",
                          "/Eventlog[@name='Secs']@value", "Seconds",
                          "/Eventlog/Entry/text()", "details"
                          ]
}

```

```
Now my question is, I was able get every line in the above xml in a each message, but i'm unable to get all the log lines in a single message.

```

Anyone can assist ?

Thanks

---

<div class="post-metadata">

**Author:** ![kishorerv93](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kishorerv93/32/47194_2.png) [@kishorerv93](https://discuss.elastic.co/u/kishorerv93)\
**Post date:** [May 31, 2019, 2:56pm UTC](https://discuss.elastic.co/t/multiline-pattern-setting-for-multiple-loglines-in-xml-file/183618/2 "2019-05-31T14:56:02Z")

</div>

````auto
```multiline.pattern: '^<Entry|^=[a-z]'
    multiline.negate : false
    multiline.match: after```

My logstash.conf
input{
 beats {
     port => 5044
}

}
filter{
  xml{
      source => message
      store_xml => true
      target => "doc"
      xpath => ["/Eventlog[@name='ThreadId']@value", "ThreadId",
                        "/Eventlog[@name='Thread']@value", "Thread",
                        "/Eventlog[@name='Secs']@value", "Seconds",
                        "/Eventlog/Entry/text()", "details"
                        ]
}

  Now my question is, I was able get every line in the above xml in a each message, but i'm unable to get all the log lines in a single message.

Anyone can assist ?

Thanks

````

Reply

### This topic will close a month after the last reply.

Bookmark Share Flag Reply

Watching

You will receive notifications because you created this topic.

### Suggested Topics

| Topic | Replies | Views | Activity |
| --- | --- | --- | --- |
| [Unable to start elasticsearch after creating cert for http communication](https://discuss.elastic.co/t/unable-to-start-elasticsearch-after-creating-cert-for-http-communication/175037/14) [3](https://discuss.elastic.co/t/unable-to-start-elasticsearch-after-creating-cert-for-http-communication/175037/14) | | | |

[Elasticsearch](https://discuss.elastic.co/c/elasticsearch)

[stack-security](https://discuss.elastic.co/tags/stack-security)|[15](https://discuss.elastic.co/t/multiline-pattern-setting-for-multiple-loglines-in-xml-file/183618)|159|[Apr 5](https://discuss.elastic.co/t/unable-to-start-elasticsearch-after-creating-cert-for-http-communication/175037/16)|  
|[How to remove agent.\* and ecs.version?](https://discuss.elastic.co/t/how-to-remove-agent-and-ecs-version/183643)

[Filebeat](https://discuss.elastic.co/c/beats/filebeat)|[3](https://discuss.elastic.co/t/multiline-pattern-setting-for-multiple-loglines-in-xml-file/183618)|19|[1h](https://discuss.elastic.co/t/how-to-remove-agent-and-ecs-version/183643/4)|  
|[Help needed for setup.template.append\_fields usage](https://discuss.elastic.co/t/help-needed-for-setup-template-append-fields-usage/183701)

[Filebeat](https://discuss.elastic.co/c/beats/filebeat)|[0](https://discuss.elastic.co/t/multiline-pattern-setting-for-multiple-loglines-in-xml-file/183618)|7|[5h](https://discuss.elastic.co/t/help-needed-for-setup-template-append-fields-usage/183701/1)|  
|[Multiline JSON not importing to fields in ElasticSearch - do I need Logstash?](https://discuss.elastic.co/t/multiline-json-not-importing-to-fields-in-elasticsearch-do-i-need-logstash/183695)

[Filebeat](https://discuss.elastic.co/c/beats/filebeat)|[0](https://discuss.elastic.co/t/multiline-pattern-setting-for-multiple-loglines-in-xml-file/183618)|11|[5h](https://discuss.elastic.co/t/multiline-json-not-importing-to-fields-in-elasticsearch-do-i-need-logstash/183695/1)|  
|[【filebeat output.file】when the output filebeat has been deleted，it wont be created agian automatically](https://discuss.elastic.co/t/filebeat-output-file-when-the-output-filebeat-has-been-deleted-it-wont-be-created-agian-automatically/183675)

[Filebeat](https://discuss.elastic.co/c/beats/filebeat)|[0](https://discuss.elastic.co/t/multiline-pattern-setting-for-multiple-loglines-in-xml-file/183618)|8|[7h](https://discuss.elastic.co/t/filebeat-output-file-when-the-output-filebeat-has-been-deleted-it-wont-be-created-agian-automatically/183675/1)|

### There are [2 unread](https://discuss.elastic.co/unread) and [211 new](https://discuss.elastic.co/new) topics remaining, or browse other topics in [Filebeat](https://discuss.elastic.co/c/beats/filebeat)

© 2018. All Rights Reserved - Elasticsearch

- Elasticsearch is a trademark of Elasticsearch BV, registered in the U.S. and in other countries
- [Trademarks](https://www.elastic.co/legal/trademarks)
- [Terms](https://www.elastic.co/legal/terms-of-use)
- [Privacy](https://www.elastic.co/legal/privacy-policy)
- [Brand](https://www.elastic.co/brand)
- [Code of Conduct](https://www.elastic.co/community/codeofconduct)

Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant logo are trademarks of the [Apache Software Foundation](http://www.apache.org/) in the United States and/or other countries.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 28, 2019, 2:56pm UTC](https://discuss.elastic.co/t/multiline-pattern-setting-for-multiple-loglines-in-xml-file/183618/3 "2019-06-28T14:56:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
