# Problem with Multiline pattern in Filebeat

**URL:** <https://discuss.elastic.co/t/problem-with-multiline-pattern-in-filebeat/91762>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [July 4, 2017, 11:54am UTC](https://discuss.elastic.co/t/problem-with-multiline-pattern-in-filebeat/91762 "2017-07-04T11:54:18Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![purvang](https://avatars.discourse-cdn.com/v4/letter/p/dfb087/32.png) [@purvang](https://discuss.elastic.co/u/purvang)\
**Post date:** [July 4, 2017, 11:54am UTC](https://discuss.elastic.co/t/problem-with-multiline-pattern-in-filebeat/91762/1 "2017-07-04T11:54:18Z")

</div>

Hi Team,

I am trying to use multiline pattern in filebeat to append multiline code in specific log

Below is my log pattern :

```auto
04 Jul 2017 14:47:35,982 [INFO] http-bio-48080-exec-6 [AUTH]: [8548c77c-0296-4056-ade8-6f6d37c4ac8c] [login] [0:0:0:0:0:0:0:1] [aaa] [-NA-] [-NA-] [-NA-]: Response
 -- Response Details --

```

Below is the pattern which I have used in the filebeat multiline configuration .

```auto
multiline.pattern : '^\[0-9]{2} \b\w+\b [0-9]{4} [0-9]{2}:[0-9]{2}:[0-9]{2},[0-9]{3}'
multiline.negate: true
multiline.match: after

```

Problem : its not giving any compilation error but its not appending new line string ( i.e : -- Response Details -- )

Kindly suggest changes

Thanks

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [July 4, 2017, 7:56pm UTC](https://discuss.elastic.co/t/problem-with-multiline-pattern-in-filebeat/91762/2 "2017-07-04T19:56:17Z")

</div>

I think there is a problem with the pattern. Try using:

```auto
multiline.pattern: '^[0-9]{2} \b\w+\b [0-9]{4} [0-9]{2}:[0-9]{2}:[0-9]{2},[0-9]{3}'

```

I tested it here [https://play.golang.org/p/WoDQUH6jfA](https://play.golang.org/p/WoDQUH6jfA)

---

<div class="post-metadata">

**Author:** ![purvang](https://avatars.discourse-cdn.com/v4/letter/p/dfb087/32.png) [@purvang](https://discuss.elastic.co/u/purvang)\
**Post date:** [July 5, 2017, 4:20am UTC](https://discuss.elastic.co/t/problem-with-multiline-pattern-in-filebeat/91762/3 "2017-07-05T04:20:46Z")

</div>

> [@purvang](#):
>
> '^[0-9]{2} \b\w+\b [0-9]{4} [0-9]{2}:[0-9]{2}:[0-9]{2},[0-9]{3}'

Hi Andrew,

Thanks for reply.

I have tried with your suggested pattern but still problem persist.

Kindly help to resolve.

Thanks

---

<div class="post-metadata">

**Author:** ![purvang](https://avatars.discourse-cdn.com/v4/letter/p/dfb087/32.png) [@purvang](https://discuss.elastic.co/u/purvang)\
**Post date:** [July 5, 2017, 5:34am UTC](https://discuss.elastic.co/t/problem-with-multiline-pattern-in-filebeat/91762/4 "2017-07-05T05:34:56Z")

</div>

Hi Andrew,

I have tried to test suggested pattern in [https://play.golang.org/](https://play.golang.org/)

I have also tested it with multiline.negate : true / false both

Its showing proper output with true and false with all the lines of log.

But unfortunately its not appending in processed log.

PFA of below listed files for your reference

1. snap of suggested pattern testing in tool :  
 ![](https://us1.discourse-cdn.com/elastic/original/3X/4/2/420126b488153f1d8cb253fe90308f0ac6d3d4d6.png)
2. snap of fileBeat log : ![](https://us1.discourse-cdn.com/elastic/original/3X/e/9/e9cddc4813a91cea2857e26500822ec390394937.png)
3. Log file from which log processed:

![](https://us1.discourse-cdn.com/elastic/original/3X/2/6/264bf3edec83ffb058a18b4d1b0a7ac452b43ce1.png)  
4. filebeat.yml file which I use for configuration :

 ![](https://us1.discourse-cdn.com/elastic/original/3X/7/c/7cbef8f7ae0f92c48b9e1623d4c8873a298048af.png)  
Please check and let me know in case of any other information require.

Thanks

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [July 5, 2017, 12:17pm UTC](https://discuss.elastic.co/t/problem-with-multiline-pattern-in-filebeat/91762/5 "2017-07-05T12:17:03Z")

</div>

have you tried to set `multiline.negate: true`?

---

<div class="post-metadata">

**Author:** ![purvang](https://avatars.discourse-cdn.com/v4/letter/p/dfb087/32.png) [@purvang](https://discuss.elastic.co/u/purvang)\
**Post date:** [July 5, 2017, 1:31pm UTC](https://discuss.elastic.co/t/problem-with-multiline-pattern-in-filebeat/91762/6 "2017-07-05T13:31:57Z")

</div>

I have tried it with true and false both.

But its not working in any case.

Thanks

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [July 5, 2017, 2:10pm UTC](https://discuss.elastic.co/t/problem-with-multiline-pattern-in-filebeat/91762/7 "2017-07-05T14:10:36Z")

</div>

The multiline setting must be configured in the prospector itself. Multiline is not global, but applied per file being processed.

Next time please share your configuration files as text files. I don't really look at screenshots I can barely read + text allows me to edit the configs.

---

<div class="post-metadata">

**Author:** ![purvang](https://avatars.discourse-cdn.com/v4/letter/p/dfb087/32.png) [@purvang](https://discuss.elastic.co/u/purvang)\
**Post date:** [July 6, 2017, 6:44am UTC](https://discuss.elastic.co/t/problem-with-multiline-pattern-in-filebeat/91762/8 "2017-07-06T06:44:26Z")

</div>

Hi Steffens,

Thanks for suggestion.

I have place multiline setting in prospector and its working now.

Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 3, 2017, 6:44am UTC](https://discuss.elastic.co/t/problem-with-multiline-pattern-in-filebeat/91762/9 "2017-08-03T06:44:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
