# Osquery Module issue

**URL:** <https://discuss.elastic.co/t/osquery-module-issue/180454>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 9, 2019, 11:49pm UTC](https://discuss.elastic.co/t/osquery-module-issue/180454 "2019-05-09T23:49:39Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![netpacket](https://avatars.discourse-cdn.com/v4/letter/n/a5b964/32.png) [@netpacket](https://discuss.elastic.co/u/netpacket)\
**Post date:** [May 9, 2019, 11:49pm UTC](https://discuss.elastic.co/t/osquery-module-issue/180454/1 "2019-05-09T23:49:40Z")

</div>

I am running filebeat 7.0 using osquery module. I am trying to override the the module's input by filtering for multiline. I am not sure why access command and placing multiline filter into the module is not working. Filebeat is ignoring my osquery module changes and still not reading the osquery json logs as single events. Could someone explain module input overriding to me?

1. According documentation: I thought I put access: block and leave the result: block on
2. Commented out result keyword and set the global var.path inside the access keyword
3. Tried commenting inputs section in the filebeat.yml and left access block in osquery.yml
4. Placed multiline filters inside the result block

I tested with dummy file and put the logs on newlines. Osquery module was able to read the json logs.

---

<div class="post-metadata">

**Author:** ![netpacket](https://avatars.discourse-cdn.com/v4/letter/n/a5b964/32.png) [@netpacket](https://discuss.elastic.co/u/netpacket)\
**Post date:** [May 10, 2019, 11:01pm UTC](https://discuss.elastic.co/t/osquery-module-issue/180454/4 "2019-05-10T23:01:58Z")

</div>

Here is my osquery yaml file:

#Module: osquery  
#Docs: [https://www.elastic.co/guide/en/beats/filebeat/7.0/filebeat-module-osquery.html](https://www.elastic.co/guide/en/beats/filebeat/7.0/filebeat-module-osquery.html)

- module: osquery

#access:  
#input:  
#multiline.pattern: '(}}}'  
#multiline.negate: true  
#multiline.match: after

---

<div class="post-metadata">

**Author:** ![netpacket](https://avatars.discourse-cdn.com/v4/letter/n/a5b964/32.png) [@netpacket](https://discuss.elastic.co/u/netpacket)\
**Post date:** [May 13, 2019, 9:46pm UTC](https://discuss.elastic.co/t/osquery-module-issue/180454/5 "2019-05-13T21:46:48Z")

</div>

This was resolved by upgrading fleet to the newest version.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 10, 2019, 9:46pm UTC](https://discuss.elastic.co/t/osquery-module-issue/180454/6 "2019-06-10T21:46:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
