# Multiline pattern works on The Go Playground but not filebeat

**URL:** <https://discuss.elastic.co/t/multiline-pattern-works-on-the-go-playground-but-not-filebeat/85604>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 12, 2017, 5:35pm UTC](https://discuss.elastic.co/t/multiline-pattern-works-on-the-go-playground-but-not-filebeat/85604 "2017-05-12T17:35:16Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![krishna\_chaitanya](https://avatars.discourse-cdn.com/v4/letter/k/b5a626/32.png) [@krishna\_chaitanya](https://discuss.elastic.co/u/krishna_chaitanya)\
**Post date:** [May 12, 2017, 5:35pm UTC](https://discuss.elastic.co/t/multiline-pattern-works-on-the-go-playground-but-not-filebeat/85604/1 "2017-05-12T17:35:16Z")

</div>

I am trying to parse xml logs which are in multiline format. The pattern works fine when I checked on [The Go Playground](https://play.golang.org/) , but not working when I actually start filebeat. Filebeat version (5.3.1) running on RHEL7

Input log:

```
<05/12/2017 08:25:19.218 EDT> [DEBUG] - [Ver: 1.0.0-SNAPSHOT] `....some message...`<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<service>
     <..>.....</..>
     <..>.....</..>
</service>

```

Pattern:

```
  multiline.pattern: '^(\<[\d]{2})'
  multiline.negate: true
  multiline.match: after

```

Go Playground:

```
matches	line
false	<05/12/2017 08:25:19.218 EDT> [DEBUG] - [Ver: 1.0.0-SNAPSHOT] ..............<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
true	<service>
true <..>
...

```

Filebeat logs in debug mode:

```
    2017-05-12T13:00:48-04:00 DBG Publish: {
      ............
      "input_type": "log",
      "message": "\u003c05/12/2017 08:25:19.218 EDT\u003e [DEBUG] - [Ver: 1.0.0-SNAPSHOT] ...... \u003c?xml version=\"1.0\" encoding=\"UTF-8\" standalone=\"yes\"?\u003e",
      "offset": 280,
      "source": "...........",
      "type": "xyz"
    }
   2017-05-12T13:00:48-04:00 DBG Publish: {
      ............
      "input_type": "log",
      "message": "\u003cservice\u003e",
      "offset": 280,
      "source": "...........",
      "type": "xyz"
    }

```

As the log shows, the second log line is being taken as separate event, instead of appending to first line. this is happening for all the lines and so each line is being read as separate event.

Any solution?

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [May 14, 2017, 10:14am UTC](https://discuss.elastic.co/t/multiline-pattern-works-on-the-go-playground-but-not-filebeat/85604/2 "2017-05-14T10:14:27Z")

</div>

can you share the more complete config? If indentation is off or multiline not put into the prospector it's not enabled.

Have you tried with [filebeat-multiline-tester](https://github.com/hartfordfive/filebeat-multiline-tester)? If it work for `filebeat-multiline-test`, but not filebeat, can you try to upgrade to 5.4 or downgrade to 5.2?

This pattern `'^\<\d{2}` should also work + should use a better performaning custom matcher in 5.3.

---

<div class="post-metadata">

**Author:** ![krishna\_chaitanya](https://avatars.discourse-cdn.com/v4/letter/k/b5a626/32.png) [@krishna\_chaitanya](https://discuss.elastic.co/u/krishna_chaitanya)\
**Post date:** [May 15, 2017, 1:36pm UTC](https://discuss.elastic.co/t/multiline-pattern-works-on-the-go-playground-but-not-filebeat/85604/3 "2017-05-15T13:36:01Z")

</div>

Thanks for the reply @steffens. It was actually my mistake, I didn't apply this configuration to required environment.  
Its working perfectly.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 12, 2017, 1:39pm UTC](https://discuss.elastic.co/t/multiline-pattern-works-on-the-go-playground-but-not-filebeat/85604/4 "2017-06-12T13:39:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
