# Wrapping Multiline log on filebeat for the below logs

**URL:** <https://discuss.elastic.co/t/wrapping-multiline-log-on-filebeat-for-the-below-logs/238804>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [June 26, 2020, 7:30am UTC](https://discuss.elastic.co/t/wrapping-multiline-log-on-filebeat-for-the-below-logs/238804 "2020-06-26T07:30:39Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![shekharkhatri](https://avatars.discourse-cdn.com/v4/letter/s/977dab/32.png) [@shekharkhatri](https://discuss.elastic.co/u/shekharkhatri)\
**Post date:** [June 26, 2020, 7:30am UTC](https://discuss.elastic.co/t/wrapping-multiline-log-on-filebeat-for-the-below-logs/238804/1 "2020-06-26T07:30:39Z")

</div>

Hello everyone!

I am trying to ingest a log that looks something like this:

```auto
*144*04:30:19 SOME EVENT
06:17:52 -> TRANSACTION START
06:17:52 .... LOG DATA
06:18:49 <- TRANSACTION END
06:17:52 -> TRANSACTION START
06:17:52 .... LOG DATA
*144*04:30:19 SOME RANDOM EVENT
06:17:54 .... LOG DATA
06:18:49 <- TRANSACTION END

```

This log comes in multiple line so it needs to be wrapped into a single event. Basically, in this log an event can be of two types, one event is within the block TRANSACTION START - TRANSACTION END, the second event is anything that comes outside the TRANSACTION blocks. What I is require is, events like the following from the log:

Event 1:

```auto
*144*04:30:19 SOME EVENT

```

Event 2:

```auto
06:17:52 -> TRANSACTION START
06:17:52 .... LOG DATA
06:18:49 <- TRANSACTION END

```

Event 3:

```auto
06:17:52 -> TRANSACTION START
06:17:52 .... LOG DATA
*144*04:30:19 SOME RANDOM EVENT
06:17:54 .... LOG DATA
06:18:49 <- TRANSACTION END

```

I was able to acquire the result like Event 1 and 2 using the following configuration:

```auto
multiline.pattern: (^(?:([01]?\d|2[0-3]):([0-5]?\d):)?([0-5]?\d) -> TRANSACTION START)|(\*[0-9]+\*[0-9]{2}:[0-9]{2}:[0-9]{2}\s.*)
multiline.negate: true
multiline.match: after

```

So what it does is looks for the line with TRANSACTION START and wraps the following lines into it. Or, looks the pattern like \*{NUMBER}\* and wraps the following line into it. It has provided me with the two events. However, there are conditions where the  
\*{NUMBER}\* might appear within the TRANSACTION block. On those conditions I need to put it with in the TRANSACTION block rather than marking it as an independent event.

I cannot find a possible solution to this specific problem. If this explanation is not quite clear I am happy to explain it further. Would love to know if anybody has encountered this situation and how you solved it. Big thanks in advance. 😁

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 24, 2020, 9:30am UTC](https://discuss.elastic.co/t/wrapping-multiline-log-on-filebeat-for-the-below-logs/238804/2 "2020-07-24T09:30:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
