# Multiple Log type

**URL:** <https://discuss.elastic.co/t/multiple-log-type/140516>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [July 18, 2018, 10:48am UTC](https://discuss.elastic.co/t/multiple-log-type/140516 "2018-07-18T10:48:54Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Suresh\_Pal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/suresh_pal/32/31571_2.png) [@Suresh\_Pal](https://discuss.elastic.co/u/Suresh_Pal)\
**Post date:** [July 18, 2018, 10:48am UTC](https://discuss.elastic.co/t/multiple-log-type/140516/1 "2018-07-18T10:48:54Z")

</div>

Hi Team,

Hope you all are doing great.

I have a question regarding the different log type in filebeat. I have configured two prospectors and used different log type but at my kibana dashboard it shows only doc, while i have not set any log type as doc.

here is my filebeat configuartion.

- type: log  
enabled: true  
paths:

tried both of them but none worked.

multiline.pattern: '^(([0-9]{4}-[0-9]{2}-[0-9]{2})|([a-zA-z]{3} [0-9]{2}, [0-9]{4} [0-9]{2}:[0-9]{2}:[0-9]{2} [AM|PM])|([0-9]{2}-[a-zA-z]{3}-[0-9]{4})|([a-zA-z]{3} [a-zA-z]{3} [0-9]{2} [0-9]{2}:[0-9]{2}:[0-9]{2}))'  
multiline.negate: true  
multiline.match: after

- type: log  
enabled: true  
paths:

tried both of them but none worked.

multiline.pattern: '^(([0-9]{4}-[0-9]{2}-[0-9]{2})|([a-zA-z]{3} [0-9]{2}, [0-9]{4} [0-9]{2}:[0-9]{2}:[0-9]{2} [AM|PM])|([0-9]{2}-[a-zA-z]{3}-[0-9]{4})|([a-zA-z]{3} [a-zA-z]{3} [0-9]{2} [0-9]{2}:[0-9]{2}:[0-9]{2}))'  
multiline.negate: true  
multiline.match: after

In my logstash config i'm using this pattern.

if [type] == "db\_log" {  
grok {  
match =\> ["message", "%{TIMESTAMP\_ISO8601:timetamp %{NOTSPACE} %{INT:line} %{NOTSPACE} %{LOGLEVEL:loglevel} (?:- Tenant Name 🙂 %{WORD:TENANT\_NAME} (?:GlobalConnectionPool - Active Connections :)%{WORD:Active\_Connections} %{NOTSPACE} (?:Idle Connections 🙂 %{WORD:Idle\_Connection}"]  
}

Please help.  
Thanks

---

<div class="post-metadata">

**Author:** ![Andrew\_Cholakian1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrew_cholakian1/32/3612_2.png) [@Andrew\_Cholakian1](https://discuss.elastic.co/u/Andrew_Cholakian1)\
**Post date:** [July 18, 2018, 10:52pm UTC](https://discuss.elastic.co/t/multiple-log-type/140516/2 "2018-07-18T22:52:09Z")

</div>

Can you post some sample data? Are you referring to `_type` or `type`. `_type` should be `doc`, but if you have a custom `type` field it should not be.

---

<div class="post-metadata">

**Author:** ![Suresh\_Pal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/suresh_pal/32/31571_2.png) [@Suresh\_Pal](https://discuss.elastic.co/u/Suresh_Pal)\
**Post date:** [July 19, 2018, 6:29am UTC](https://discuss.elastic.co/t/multiple-log-type/140516/3 "2018-07-19T06:29:15Z")

</div>

It worked by adding  
fields\_under\_root: true  
fields:  
type: db\_log

Thanks man.

---

<div class="post-metadata">

**Author:** ![Andrew\_Cholakian1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrew_cholakian1/32/3612_2.png) [@Andrew\_Cholakian1](https://discuss.elastic.co/u/Andrew_Cholakian1)\
**Post date:** [July 19, 2018, 4:01pm UTC](https://discuss.elastic.co/t/multiple-log-type/140516/4 "2018-07-19T16:01:20Z")

</div>

NP, glad to hear it!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 16, 2018, 4:01pm UTC](https://discuss.elastic.co/t/multiple-log-type/140516/5 "2018-08-16T16:01:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
