# XML message in catalina log

**URL:** <https://discuss.elastic.co/t/xml-message-in-catalina-log/99175>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [September 1, 2017, 11:09pm UTC](https://discuss.elastic.co/t/xml-message-in-catalina-log/99175 "2017-09-01T23:09:36Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Wayne\_Taylor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wayne_taylor/32/45984_2.png) [@Wayne\_Taylor](https://discuss.elastic.co/u/Wayne_Taylor)\
**Post date:** [September 1, 2017, 11:09pm UTC](https://discuss.elastic.co/t/xml-message-in-catalina-log/99175/1 "2017-09-01T23:09:36Z")

</div>

Hi Team,

I have my catalina.out parsed but once exception it misses XML over multi line. I need some help to get this working.

Below is my config thus far:

```
filebeat.prospectors:
- document_type: logs
  paths:
  - /Users/wtaylor/Downloads/logstash-5.3.0/bin/example.txt

multiline:
- pattern: "^20%{YEAR}-%{MONTHNUM}-%{MONTHDAY} %{HOUR}:%{MINUTE}:%{SECOND}"
- negate: true
- match: after

output.logstash:
 hosts: ["127.0.0.1:3335"]

```

Below is an example of what is matching and what isn't

Match:

```
{
        "server" => "prod1",
    "@timestamp" => 2017-09-01T23:06:42.342Z,
        "offset" => 1807,
      "@version" => "1",
    "input_type" => "log",
          "beat" => {
        "hostname" => "MB-C02TF1QUGTFM",
            "name" => "MB-C02TF1QUGTFM",
         "version" => "5.5.2"
    },
          "host" => "MB-C02TF1QUGTFM",
        "source" => "/Users/wtaylor/Downloads/logstash-5.3.0/bin/example.txt",
       "message" => "2017-08-31T14:25:26.074|INFO|ACPU2|ABP|com.aircell.shared.web.servlet.SessionInfoLoggingFilter.doFilter:39|Id:_172.19.131.144|Thread:http-nio-1000-exec-12|SessionInfoLoggingFilter :: doFilter",
          "type" => "logs",
          "tags" => [
        [0] "beats_input_codec_plain_applied"
    ]
}

```

Miss:

XML Object in log over multi lines:

```
<java version="1.8.0_65" class="java.beans.XMLDecoder">
 <object class="com.aircell.abp.model.FlightInformation">
    <void property="VersionNo">
   <string>P15340_RevKK</string>
  </void>
  <void property="aircraftTailNumber">
   <string>N270AK</string>
  </void>
 </object>
</java>

```

Any help greatly appreciated.

Wayne

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [September 4, 2017, 1:30pm UTC](https://discuss.elastic.co/t/xml-message-in-catalina-log/99175/2 "2017-09-04T13:30:54Z")

</div>

You have an error in your filebeat configuration. The `multiline` settings are per prospector, not global. Indenting all multiline settings by 2 spaces should help.

The syntax used in the `pattern` setting is not correct. One can only use plain regular expressions. Also `%{<name>}` is not supported by beats. Try: `'%20\d{2}-\d{2}-\d{2} \d{2}:\d{2}:\d{2}'`. Don't use double quotes for regular expressions in YAML configuration files.

With multiline one tries to capture the 'structure' of the log, not the contents so to say. If you're still having problem please include some more consecutive log lines.

---

<div class="post-metadata">

**Author:** ![Wayne\_Taylor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wayne_taylor/32/45984_2.png) [@Wayne\_Taylor](https://discuss.elastic.co/u/Wayne_Taylor)\
**Post date:** [September 4, 2017, 2:11pm UTC](https://discuss.elastic.co/t/xml-message-in-catalina-log/99175/3 "2017-09-04T14:11:56Z")

</div>

Hi @steffens, thanks but same issue.

Here is my config as per request:  
filebeat.prospectors:  
- document\_type: abp\_logs  
paths:  
- /Users/wtaylor/Downloads/logstash-5.3.0/bin/example.txt

```
multiline:
- pattern: '%20\d{2}-\d{2}-\d{2} \d{2}:\d{2}:\d{2}'
- negate: true
- match: after

output.logstash:
 hosts: ["127.0.0.1:3335"]![02 AM|690x375](upload:/

```

Log Messages attached - sorry but the XML gets truncated so needed as image

 ![02 AM](https://us1.discourse-cdn.com/elastic/original/3X/d/0/d02e6b3e34818e092e64cd5fdad90957c23ab8ea.png)

Line 6 where the XML begins shows and then each line of the xml shows

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [September 5, 2017, 3:34pm UTC](https://discuss.elastic.co/t/xml-message-in-catalina-log/99175/4 "2017-09-05T15:34:55Z")

</div>

Please, copy and paste contents. No screenshots. Not everyone might be able to see your screenshots + I'm not willing to type out the screenshot for testing.

Check the actual date pattern in your screenshot and the regular expression you have configured. They clearly do not match. Consider: `'^\d{4}-\d{2}-\d{2}T\d{2}:\d{2}:\d{2}.\d{3}\|'`.

For tips on testing multiline also check the filebeat documentation.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 3, 2017, 3:35pm UTC](https://discuss.elastic.co/t/xml-message-in-catalina-log/99175/5 "2017-10-03T15:35:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
