# Why is the error log being sent divided?

**URL:** <https://discuss.elastic.co/t/why-is-the-error-log-being-sent-divided/315192>\
**Category:** Logstash\
**Created:** [September 26, 2022, 5:03pm UTC](https://discuss.elastic.co/t/why-is-the-error-log-being-sent-divided/315192 "2022-09-26T17:03:50Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![erwin339](https://avatars.discourse-cdn.com/v4/letter/e/2bfe46/32.png) [@erwin339](https://discuss.elastic.co/u/erwin339)\
**Post date:** [September 26, 2022, 5:03pm UTC](https://discuss.elastic.co/t/why-is-the-error-log-being-sent-divided/315192/1 "2022-09-26T17:03:50Z")

</div>

I am sending error and fatal logs, these have multiple lines, so the multiline is configured like this:  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/8/e8028c48b617c961da8153f3201e204bbc845444.png)

filebeat multiline:  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/5/b5669033fa16075740816d64e4c1e21c5bc7b42e.png)

This is throwing me an error:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/a/5a3edff4a455662d87c9d406319f53e98f214d56.png)  
my error and fatal log have this structure:

```auto
<log4j:event logger="LogGeneratorApp.MainForm" timestamp="1664208384844" level="ERROR" thread="1"><log4j:message>This is a test log message</log4j:message><log4j:properties><log4j:data name="log4net:UserName" value="TEN\60085367" /><log4j:data name="log4jmachinename" value="TAMP00043541" /><log4j:data name="log4japp" value="LogGeneratorApp.exe" /><log4j:data name="log4net:HostName" value="TAMP00043541" /></log4j:properties><log4j:throwable>System.Exception: This is a test log message
   en LogGeneratorApp.MainForm.SendToLog(String level, String message)</log4j:throwable><log4j:locationInfo class="LogGeneratorApp.MainForm" method="SendToLog" file="" line="0" /></log4j:event>

```

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/4/943c032c00e1df9cc213faa5befcdccad2316823.png)

and in kibana I can see that the log sends it like this:

part 1:  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/8/5834720f9618544b799668bfb8ac8e58c8342438.png)

par2:  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/3/c3f3e57c99c76d25d5cf26a7ac3346890b69aa8e.png)

Note in the image that the first line and the second are sent separately.  
This happens to me when I send two fatal or two errors or a fatal and an error from different apps.  
If I only send from one, I have no problems.

---

<div class="post-metadata">

**Author:** ![erwin339](https://avatars.discourse-cdn.com/v4/letter/e/2bfe46/32.png) [@erwin339](https://discuss.elastic.co/u/erwin339)\
**Post date:** [September 26, 2022, 6:08pm UTC](https://discuss.elastic.co/t/why-is-the-error-log-being-sent-divided/315192/2 "2022-09-26T18:08:56Z")

</div>

Resolved. At first I was configuring a multiline for all inputs so I tried assigning a multiline for each input just like the processors and it corrected the error.

```auto
filebeat.inputs:

- type: filestream
  id: tricentisT-app4
  enabled: true
  paths:
    - C:\Users\60085367\Desktop\ServerTest3\3_Log_Generados1\*
  processors:
  - add_fields: 
      fields: 
        V_APP_NAME: TricentisT.Log.Tester1
  
  parsers:
    - multiline:
        type: pattern
        pattern: '^<log4j:event.*'
        negate: true
        match: after

- type: filestream
  id: detection-app5
  enabled: true
  paths:
    - C:\Users\60085367\Desktop\ServerTest3\3_Log_Generados2\*
  processors:
  - add_fields: 
      fields: 
        V_APP_NAME: Detection.Log.Tester2

  parsers:
    - multiline:
        type: pattern
        pattern: '^<log4j:event.*'
        negate: true
        match: after

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 24, 2022, 6:08pm UTC](https://discuss.elastic.co/t/why-is-the-error-log-being-sent-divided/315192/3 "2022-10-24T18:08:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
