# Specify multiline prospector and pipeline for elasticsearch output

**URL:** <https://discuss.elastic.co/t/specify-multiline-prospector-and-pipeline-for-elasticsearch-output/175445>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [April 4, 2019, 2:56pm UTC](https://discuss.elastic.co/t/specify-multiline-prospector-and-pipeline-for-elasticsearch-output/175445 "2019-04-04T14:56:46Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![thola](https://avatars.discourse-cdn.com/v4/letter/t/3be4f8/32.png) [@thola](https://discuss.elastic.co/u/thola)\
**Post date:** [April 4, 2019, 2:56pm UTC](https://discuss.elastic.co/t/specify-multiline-prospector-and-pipeline-for-elasticsearch-output/175445/1 "2019-04-04T14:56:46Z")

</div>

I am new to filebeat and would like to set up a prospector reading a log file in which one entry is of the following form of a http request and response. It is multiline and i am not sure how to specify, that the [RESPONSE] and [REQUEST] blocks should be part of the same entry.  
I also would like to use some pipeline to pass this in json format to elasticsearch output. Which processors should i use?

[REQUEST (_webAPIHandlers).Download-fm] [155438493.626241] [2019-04-04 15:35:36 +0200]  
GET /minio/download/bucket/lethe1policy.json?token=eyJhbGciOiJIUzUxMiIsInR5cCI6IkpXVCJ9.eyJleHAiOjE1NTQzODQ5OTYsInN1YiI6ImFkbWluIn0.3vAMrQbU0MvT3vKoO4m-Mfc3uEyYR7Y7zddE24ogPIY1ZdFKBOVRYKekJCLB7z\_132G5kiNpS7wP9ZMc0RhmZw  
Host: zon-psr-sub001.zontal.vmserver:9000  
Accept-Language: en-US,en;q=0.5  
Accept-Encoding: gzip, deflate  
Dnt: 1  
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0  
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,_/\*;q=0.8  
Referer: [http://zon-psr-sub001.zontal.vmserver:9000/minio/bucket/](http://zon-psr-sub001.zontal.vmserver:9000/minio/bucket/)  
Connection: keep-alive  
Upgrade-Insecure-Requests: 1

[RESPONSE] [155438493.626241] [2019-04-04 15:35:36 +0200]  
200 OK  
Cache-Control: no-store  
X-Xss-Protection: 1; mode=block  
Accept-Ranges: bytes  
Last-Modified: Thu, 04 Apr 2019 13:35:01 GMT  
Content-Length: 263  
Content-Disposition: attachment; filename="lethe1policy.json"  
Vary: Origin  
Content-Security-Policy: block-all-mixed-content  
X-Amz-Request-Id: 159248DD3222DC74  
Server: Minio/RELEASE.2019-03-13T21-59-47Z  
Etag: "772755e428b7d836c106dbeda54099da"  
Content-Type: application/json

---

<div class="post-metadata">

**Author:** ![Michal\_Pristas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michal_pristas/32/46639_2.png) [@Michal\_Pristas](https://discuss.elastic.co/u/Michal_Pristas)\
**Post date:** [April 5, 2019, 10:40am UTC](https://discuss.elastic.co/t/specify-multiline-prospector-and-pipeline-for-elasticsearch-output/175445/2 "2019-04-05T10:40:00Z")

</div>

Hey @thola  
if you follow an example [here](https://www.elastic.co/guide/en/beats/filebeat/current/multiline-examples.html)

you can specify a pattern to be `'^\[REQUEST'`

so having configuration

```auto
multiline.pattern: '^\['
multiline.negate: true
multiline.match: after

```

will include everything which comes after `[REQUEST` as a single message up to the point where another occurrence of `[REQUEST` is found

if there are another logs in the mix you can also use `multiline.flush_pattern` for termination of the line  
including

```auto
multiline.flush_pattern: '^Content-Type: '

```

after occurrence of content type message be considered a whole.  
also you may think about `max-lines` options if this is something deterministic

---

<div class="post-metadata">

**Author:** ![thola](https://avatars.discourse-cdn.com/v4/letter/t/3be4f8/32.png) [@thola](https://discuss.elastic.co/u/thola)\
**Post date:** [April 5, 2019, 12:26pm UTC](https://discuss.elastic.co/t/specify-multiline-prospector-and-pipeline-for-elasticsearch-output/175445/3 "2019-04-05T12:26:27Z")

</div>

What i basically want to do is make a json out of the lines with : rest-of-the-line. and have twi different fields for that, one for the request part and one for the response part. Both are part of one log entry

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 3, 2019, 12:26pm UTC](https://discuss.elastic.co/t/specify-multiline-prospector-and-pipeline-for-elasticsearch-output/175445/4 "2019-05-03T12:26:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
