# Problems with parsing multiline

**URL:** <https://discuss.elastic.co/t/problems-with-parsing-multiline/52176>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [June 8, 2016, 8:30am UTC](https://discuss.elastic.co/t/problems-with-parsing-multiline/52176 "2016-06-08T08:30:10Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![SergeyParamoshkin](https://avatars.discourse-cdn.com/v4/letter/s/74df32/32.png) [@SergeyParamoshkin](https://discuss.elastic.co/u/SergeyParamoshkin)\
**Post date:** [June 8, 2016, 8:30am UTC](https://discuss.elastic.co/t/problems-with-parsing-multiline/52176/1 "2016-06-08T08:30:10Z")

</div>

Hi. I have a problem, I use a multiline parsing with this configuration.

```auto
multiline:
        pattern: ^\[
        negate: true
        match: after

```

```auto
INFO 2016-06-08 10:11:08,241 Controller.py:265 - Heartbeat response received (id = 131593)
INFO 2016-06-08 10:11:08,241 ActionQueue.py:100 - Adding STATUS_COMMAND for component METRICS_MONITOR of service AMBARI_METRICS of cluster rnd_dwh to the queue.
INFO 2016-06-08 10:11:08,336 ActionQueue.py:100 - Adding STATUS_COMMAND for component HBASE_REGIONSERVER of service HBASE of cluster rnd_dwh to the queue.
INFO 2016-06-08 10:11:08,421 ActionQueue.py:100 - Adding STATUS_COMMAND for component DATANODE of service HDFS of cluster rnd_dwh to the queue.
INFO 2016-06-08 10:11:08,467 ActionQueue.py:100 - Adding STATUS_COMMAND for component NODEMANAGER of service YARN of cluster rnd_dwh to the queue.

```

it all turns out the same message in logstash.

This is a bug? or am I wrong tune filebeat

system configuration  
filebeat version 1.2.3 (amd64)  
Red Hat Enterprise Linux Server release 6.7 (Santiago)

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [June 8, 2016, 11:25am UTC](https://discuss.elastic.co/t/problems-with-parsing-multiline/52176/2 "2016-06-08T11:25:42Z")

</div>

why did you set `negate: true`? Having `negate: true` all lines not matching the pattern will be merged. For example run this test script: [https://play.golang.org/p/qtELnY1Q73](https://play.golang.org/p/qtELnY1Q73)

You can use the script to test some sample logs including multiline events (highly recommended). All lines starting with `true` will be merged into an multiline event.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 12, 2016, 11:16am UTC](https://discuss.elastic.co/t/problems-with-parsing-multiline/52176/3 "2016-06-12T11:16:35Z")

</div>

Why is your pattern `^\[`? None of the lines you've posted start with a square bracket.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 29, 2016, 8:30am UTC](https://discuss.elastic.co/t/problems-with-parsing-multiline/52176/4 "2016-06-29T08:30:09Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
