# Parse the data using filebeat

**URL:** https://discuss.elastic.co/t/parse-the-data-using-filebeat/160407
**Category:** Beats
**Tags:** filebeat
**Created:** [December 11, 2018, 4:12pm UTC](https://discuss.elastic.co/t/parse-the-data-using-filebeat/160407 "2018-12-11T16:12:33Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![leandro\_matos\_pereir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandro_matos_pereir/32/65342_2.png) [@leandro\_matos\_pereir](https://discuss.elastic.co/u/leandro_matos_pereir)
#### Post date: [December 11, 2018, 4:12pm UTC](https://discuss.elastic.co/t/parse-the-data-using-filebeat/160407/1 "2018-12-11T16:12:33Z")

</div>

Good afternoon.

I'm having a hard time filtering information from filebeat / logstash.

Here's the current scenario I'm using:

filebeat: Installed on 06 servers to collect a log consisting of multi-lines, attached an example of how it is found  
logstash: receives the filebeat information and sends to the elastic  
elasticsearch: receives the information in NFS and the data is viewed in Kibana

Logstash by default reads one line at a time and because it has several rows it does not understand that it is part of the same block, as my log is multi-line, when doing the search it can not understand and the data is separated which makes it difficult in information.

Could someone show me some configuration example of how I could do these tests?

 ![Capture](https://us1.discourse-cdn.com/elastic/original/3X/5/8/58bf351f7393e29aca11895fdbb7adaf9987fee4.png)

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [January 8, 2019, 4:27pm UTC](https://discuss.elastic.co/t/parse-the-data-using-filebeat/160407/2 "2019-01-08T16:27:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
