# Parsing Log4net with Filebeat

**URL:** <https://discuss.elastic.co/t/parsing-log4net-with-filebeat/64180>\
**Category:** Beats\
**Created:** [October 27, 2016, 6:29pm UTC](https://discuss.elastic.co/t/parsing-log4net-with-filebeat/64180 "2016-10-27T18:29:08Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![mmehraban](https://avatars.discourse-cdn.com/v4/letter/m/258eb7/32.png) [@mmehraban](https://discuss.elastic.co/u/mmehraban)\
**Post date:** [October 27, 2016, 6:29pm UTC](https://discuss.elastic.co/t/parsing-log4net-with-filebeat/64180/1 "2016-10-27T18:29:09Z")

</div>

Hi guys,  
I want to pars log4net Files which is shipping from filebeat to Logstash but I have difficulty with multiline in Filebeat?  
What is the best way to do it?

Any help or suggestion would be appreciated

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [October 27, 2016, 6:53pm UTC](https://discuss.elastic.co/t/parsing-log4net-with-filebeat/64180/2 "2016-10-27T18:53:24Z")

</div>

Have you looked over the examples and config reference?

[Multiline examples](https://www.elastic.co/guide/en/beats/filebeat/current/multiline-examples.html)  
[Multiline config reference](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-filebeat-options.html#multiline)

What specific problem are you having with multiline?

---

<div class="post-metadata">

**Author:** ![mmehraban](https://avatars.discourse-cdn.com/v4/letter/m/258eb7/32.png) [@mmehraban](https://discuss.elastic.co/u/mmehraban)\
**Post date:** [October 27, 2016, 6:56pm UTC](https://discuss.elastic.co/t/parsing-log4net-with-filebeat/64180/3 "2016-10-27T18:56:29Z")

</div>

I don't know how change grok pattern to multiline [pattern.it](http://pattern.it) is confusing

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [October 27, 2016, 8:31pm UTC](https://discuss.elastic.co/t/parsing-log4net-with-filebeat/64180/4 "2016-10-27T20:31:01Z")

</div>

Do you have some sample log lines that you can share? If so, please also specify which lines are to be grouped into a single event.

---

<div class="post-metadata">

**Author:** ![mmehraban](https://avatars.discourse-cdn.com/v4/letter/m/258eb7/32.png) [@mmehraban](https://discuss.elastic.co/u/mmehraban)\
**Post date:** [October 27, 2016, 8:36pm UTC](https://discuss.elastic.co/t/parsing-log4net-with-filebeat/64180/5 "2016-10-27T20:36:05Z")

</div>

2016-10-17 03:20:37,690 [319299] ERROR Global - Unhandled application error  
System.ArgumentOutOfRangeException: Specified argument was out of the range of valid values.  
Parameter name: count  
at System.Web.HttpRequest.BinaryRead(Int32 count)  
at Telmetrics.Madison.Core.Helper.WebHelper.ReadRequestDataAsByteArray() in C:\BuildAgent\work\c32ad01eae0d37ff\src\OrderingAndReports\Telmetrics.Madison.Core\Helper\WebHelper.cs:line 27  
at Telmetrics.Madison.Core.Helper.WebHelper.ReadRequestDataAsString() in C:\BuildAgent\work\c32ad01eae0d37ff\src\OrderingAndReports\Telmetrics.Madison.Core\Helper\WebHelper.cs:line 42  
at Telmetrics.Madison.WebApiService.Middleware.Logging.LoggingMiddleware.LogHttpRequest(IOwinRequest request) in C:\BuildAgent\work\c32ad01eae0d37ff\src\OrderingAndReports\Telmetrics.Madison.WebApiService\Middleware\Logging\LoggingMiddleware.cs:line 71  
at Telmetrics.Madison.WebApiService.Middleware.Logging.LoggingMiddleware.d\_\_5.MoveNext() in C:\BuildAgent\work\c32ad01eae0d37ff\src\OrderingAndReports\Telmetrics.Madison.WebApiService\Middleware\Logging\LoggingMiddleware.cs:line 46  
--- End of stack trace from previous location where exception was thrown ---  
at System.Runtime.CompilerServices.TaskAwaiter.ThrowForNonSuccess(Task task)  
at System.Runtime.CompilerServices.TaskAwaiter.HandleNonSuccessAndDebuggerNotification(Task task)  
at Microsoft.Owin.Host.SystemWeb.IntegratedPipeline.IntegratedPipelineContextStage.d\_\_5.MoveNext()  
--- End of stack trace from previous location where exception was thrown ---  
at System.Runtime.CompilerServices.TaskAwaiter.ThrowForNonSuccess(Task task)  
at System.Runtime.CompilerServices.TaskAwaiter.HandleNonSuccessAndDebuggerNotification(Task task)  
at Microsoft.Owin.Host.SystemWeb.IntegratedPipeline.IntegratedPipelineContext.d\_\_2.MoveNext()  
--- End of stack trace from previous location where exception was thrown ---  
at Microsoft.Owin.Host.SystemWeb.IntegratedPipeline.StageAsyncResult.End(IAsyncResult ar)  
at System.Web.HttpApplication.AsyncEventExecutionStep.System.Web.HttpApplication.IExecutionStep.Execute()  
at System.Web.HttpApplication.ExecuteStep(IExecutionStep step, Boolean& completedSynchronously)

This should be in one group,

---

<div class="post-metadata">

**Author:** ![djohnson](https://avatars.discourse-cdn.com/v4/letter/d/0ea827/32.png) [@djohnson](https://discuss.elastic.co/u/djohnson)\
**Post date:** [October 27, 2016, 8:47pm UTC](https://discuss.elastic.co/t/parsing-log4net-with-filebeat/64180/6 "2016-10-27T20:47:40Z")

</div>

Here's what I use for log4net:

```
  multiline:
    pattern: '^[0-9]{4}-[0-9]{2}-[0-9]{2} [0-9]{2}:[0-9]{2}:[0-9]{2}'
    negate: true
    match: after
```

---

<div class="post-metadata">

**Author:** ![mmehraban](https://avatars.discourse-cdn.com/v4/letter/m/258eb7/32.png) [@mmehraban](https://discuss.elastic.co/u/mmehraban)\
**Post date:** [October 28, 2016, 1:23pm UTC](https://discuss.elastic.co/t/parsing-log4net-with-filebeat/64180/7 "2016-10-28T13:23:56Z")

</div>

Thank you for your reply and i'm investigating the best Logstash filter to pars the [Log4net.In](http://Log4net.In) Kibana I can create Logstash-\* index but it is not showing the information yet

---

<div class="post-metadata">

**Author:** ![djohnson](https://avatars.discourse-cdn.com/v4/letter/d/0ea827/32.png) [@djohnson](https://discuss.elastic.co/u/djohnson)\
**Post date:** [October 28, 2016, 9:29pm UTC](https://discuss.elastic.co/t/parsing-log4net-with-filebeat/64180/8 "2016-10-28T21:29:53Z")

</div>

Here's my log4net filter:

```
filter {
  if "log4net" in [tags] {
    grok {
      match => { message => "(?m)%{TIMESTAMP_ISO8601:sourceTimestamp}\,%{NUMBER:threadid} %{LOGLEVEL:loglevel} %{GREEDYDATA:tempMessage}" }
    }
    mutate {
        gsub => [
          "message", "^[0-9]{4}-[0-9]{2}-[0-9]{2} [0-9]{2}:[0-9]{2}:[0-9]{2},[0-9]+ [A-Z]+ ", ""
        ]
    }
    date {
      match => ["sourceTimestamp", "YYYY-MM-dd HH:mm:ss"]
    }
    mutate {
      remove_field => ["tempMessage"]
      remove_field => ["tempHost"]
    }
  }
}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 17, 2016, 6:29pm UTC](https://discuss.elastic.co/t/parsing-log4net-with-filebeat/64180/9 "2016-11-17T18:29:18Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
