# Problem about pushing oracle alert.log to es

**URL:** <https://discuss.elastic.co/t/problem-about-pushing-oracle-alert-log-to-es/110510>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [December 6, 2017, 11:28am UTC](https://discuss.elastic.co/t/problem-about-pushing-oracle-alert-log-to-es/110510 "2017-12-06T11:28:50Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![tuankun](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tuankun/32/8590_2.png) [@tuankun](https://discuss.elastic.co/u/tuankun)\
**Post date:** [December 6, 2017, 11:28am UTC](https://discuss.elastic.co/t/problem-about-pushing-oracle-alert-log-to-es/110510/1 "2017-12-06T11:28:51Z")

</div>

Hi Guys,  
I'm trying to push oracle alert.log to es,like this:  
alert log-\>filebeat-\>logstash-\>elasticsearch

alert log format like blow:

Sun Mar 19 16:55:27 2017  
DBRM started with pid=7, OS id=21297  
Sun Mar 19 16:58:33 2017  
DIA0 started with pid=8, OS id=21299

I configured below multiline pattern in filebeat.yml (filebeat 5.6.4):

multiline.pattern: '^[A-Z]{1}[a-z]{2} [A-Z]{1}[a-z]{2} [0-9]{2} [0-9]{2}:[0-9]{2}:[0-9]{2} [0-9]{4}'  
multiline.negate: true  
multiline.match: after

but the first message missed "Sun" letters,the second message is normal,I don't know why, anybody could help me? thanks.

C:\Users\Administrator\Desktop\filebeat-5.6.4-windows-x86\_64\>filebeat.exe  
{  
"@timestamp": "2017-12-06T11:14:16.604Z",  
"beat": {  
"hostname": "TESTAP01",  
"name": "TESTAP01",  
"version": "5.6.4"  
},  
"fields": {  
"oracle\_sid": "TESTDB"  
},  
"input\_type": "log",  
**"message": " Mar** 19 16:55:27 2017\nDBRM started with pid=7, OS id=21297 ", #"Sun" is missed  
"offset": 1092,  
"source": "c:\alert\_TESTDB.log",  
"type": "oraclealertlog"  
}  
{  
"@timestamp": "2017-12-06T11:14:16.604Z",  
"beat": {  
"hostname": "TESTAP01",  
"name": "TESTAP01",  
"version": "5.6.4"  
},  
"fields": {  
"oracle\_sid": "TESTDB"  
},  
"input\_type": "log",  
"message": " **Sun** Mar 19 16:58:33 2017\nDIA0 started with pid=8, OS id=21299 \n  
n\n",  
"offset": 1158,  
"source": "c:\alert\_TESTDB.log",  
"type": "oraclealertlog"  
}

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [December 6, 2017, 2:49pm UTC](https://discuss.elastic.co/t/problem-about-pushing-oracle-alert-log-to-es/110510/2 "2017-12-06T14:49:32Z")

</div>

Please format configs and logs using the `</>` button or 3 back-ticks.

Can you share you complete filebeat config?

This looks like filebeat did read the line starting at offset 3. Do you have tail\_files enabled?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 3, 2018, 2:49pm UTC](https://discuss.elastic.co/t/problem-about-pushing-oracle-alert-log-to-es/110510/3 "2018-01-03T14:49:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
