# Auto\_flush\_interval in multiline codec plugin errors out

**URL:** https://discuss.elastic.co/t/auto-flush-interval-in-multiline-codec-plugin-errors-out/99345
**Category:** Logstash
**Created:** [September 4, 2017, 9:38pm UTC](https://discuss.elastic.co/t/auto-flush-interval-in-multiline-codec-plugin-errors-out/99345 "2017-09-04T21:38:16Z")
**Posts on this page:** 9
**Page:** 1

<div class="post-metadata">

### Author: ![amruth](https://avatars.discourse-cdn.com/v4/letter/a/43a26b/32.png) [@amruth](https://discuss.elastic.co/u/amruth)
#### Post date: [September 4, 2017, 9:38pm UTC](https://discuss.elastic.co/t/auto-flush-interval-in-multiline-codec-plugin-errors-out/99345/1 "2017-09-04T21:38:16Z")

</div>

Hi,

I am using auto\_flush\_interval in multiline codec plugin. It works fine for all the events but when it reaches the end of file, it is throwing grokparsefailure error. And when I remove auto\_flush\_interval, there are no issues(but I will be loosing the last event). Can someone please solve this issue?

Thank you

---

<div class="post-metadata">

### Author: ![amruth](https://avatars.discourse-cdn.com/v4/letter/a/43a26b/32.png) [@amruth](https://discuss.elastic.co/u/amruth)
#### Post date: [September 6, 2017, 6:14pm UTC](https://discuss.elastic.co/t/auto-flush-interval-in-multiline-codec-plugin-errors-out/99345/2 "2017-09-06T18:14:19Z")

</div>

Can someone please help me with the issue?

---

<div class="post-metadata">

### Author: ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)
#### Post date: [September 6, 2017, 6:50pm UTC](https://discuss.elastic.co/t/auto-flush-interval-in-multiline-codec-plugin-errors-out/99345/3 "2017-09-06T18:50:00Z")

</div>

It probably helps if you show your configuration and provide examples of what the data looks like.

---

<div class="post-metadata">

### Author: ![amruth](https://avatars.discourse-cdn.com/v4/letter/a/43a26b/32.png) [@amruth](https://discuss.elastic.co/u/amruth)
#### Post date: [September 7, 2017, 7:38pm UTC](https://discuss.elastic.co/t/auto-flush-interval-in-multiline-codec-plugin-errors-out/99345/4 "2017-09-07T19:38:23Z")

</div>

Here is my config,

```
input{

	file{
		path=>"/opt/file.log"
		start_position=> "beginning"
		sincedb_path => "/var/lib/sincedb.log"
		type=>"success"
		
		
		codec => multiline {
			pattern => "^entry"
			negate => true
			what => previous
			auto_flush_interval => 10
			max_lines => 100000
			max_bytes => "1000 MiB"
		}
	}
	
	file{
		path=>"/opt/file.log"
		start_position=> "beginning"
		sincedb_path => "/var/lib/sincedb_fail.log"
		type=>"failure"
		
		codec => multiline {
			pattern => "^%{TIMESTAMP_ISO8601}"
			negate => true
			what => previous
			auto_flush_interval => 10
			max_lines => 100000
			max_bytes => "1000 MiB"
		}       
	}
filter {

	if [type] == "success"{
		grok {
			match => {"message" => "Query =>\n%{GREEDYDATA:query}\nTotal query time: %{NUMBER:query_time:float}%{DATA}\[Query Timestamp\: %{NUMBER:Query_Timestamp}%{GREEDYDATA}]"}
		}
	
		mutate {
			gsub => ["Query_Timestamp","\d\d\d$",""]
			remove_field => ["message"]
			add_field =>{"component" => "Queries"}
			add_field =>{"app_name" => "XYZ"}
		}
	
		date {
			match => ["Query_Timestamp", "UNIX_MS"]
			target => "timestamp"
		}
	}
	
	if [type] == "failure"{
		if "ERROR" in [message] and "failure" in [message] {
			grok {
				match => {"message" => "%{TIMESTAMP_ISO8601:timestamp}%{GREEDYDATA} ERROR \[\] %{DATA:error} reason:%{GREEDYDATA:reason}"}
			}
		
			mutate{
				#gsub => ["timestamp",".{5}$",""]
				gsub => ["reason","\n", ""]
				gsub => ["reason", "\[\]", ""]
				strip => ["reason"]
				remove_field => ["message"]
				add_field =>{"component" => "Queries"}
				add_field =>{"app_name" => "XYZ"}
			}
			
			date {
				match => ["timestamp", "yyyy-MM-dd HH:mm:ss:SSSSSSSSS"]
				target => "timestamp"
			}
	    }
	
		else{
			drop{}
		}
	}
}

output{

	stdout{
		codec=>rubydebug
	}
}

```

And here is the data,

```
2017-04-19 14:56:01:57716 [139897046292224 rid:] [] Server: started client connection thread

2017-04-19 14:56:12:68588 [139897046292224 rid:] [] [Query Timestamp: 1492628172620975]  
2017-04-19 14:56:12:68591 [139897046292224 rid:a7213aba8ef6] [] [Query Timestamp: 1492628172620975]  
2017-04-19 14:56:12:68591 [139897046292224 rid:a7213aba8ef6] [] [Query Timestamp: 1492628172620975]  
entry=>
show tables
Total query time: 0.014951

2017-04-19 14:56:12:68591 [139897046292224 rid:a7213aba8ef6] [] [Query Timestamp: 1492628172620975] Server: query completed
2017-04-19 15:55:08:3604570 [139897046292224 rid:] [] Server: 
entry=>
show tables
Total query time: 0.014951

2017-04-19 14:56:12:68591 [139897046292224 rid:a7213aba8ef6] [] [Query Timestamp: 1492628172620975] Server: query completed
2017-04-19 15:55:08:3604570 [139897046292224 rid:] []
```

---

<div class="post-metadata">

### Author: ![amruth](https://avatars.discourse-cdn.com/v4/letter/a/43a26b/32.png) [@amruth](https://discuss.elastic.co/u/amruth)
#### Post date: [September 12, 2017, 11:11am UTC](https://discuss.elastic.co/t/auto-flush-interval-in-multiline-codec-plugin-errors-out/99345/5 "2017-09-12T11:11:11Z")

</div>

Hi, can someone please help on this issue?

---

<div class="post-metadata">

### Author: ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)
#### Post date: [September 12, 2017, 11:17am UTC](https://discuss.elastic.co/t/auto-flush-interval-in-multiline-codec-plugin-errors-out/99345/6 "2017-09-12T11:17:11Z")

</div>

Why do you have 2 file inputs for the same file? What is the desired output and what are you actually seeing?

---

<div class="post-metadata">

### Author: ![amruth](https://avatars.discourse-cdn.com/v4/letter/a/43a26b/32.png) [@amruth](https://discuss.elastic.co/u/amruth)
#### Post date: [September 19, 2017, 10:58am UTC](https://discuss.elastic.co/t/auto-flush-interval-in-multiline-codec-plugin-errors-out/99345/7 "2017-09-19T10:58:29Z")

</div>

> [@Christian\_Dahlqvist](#):
>
> Why do you have 2 file inputs for the same file?

One is to capture success transactions and the other is to capture failed transactions(they have different patterns, so reading file twice).

> [@Christian\_Dahlqvist](#):
>
> What is the desired output and what are you actually seeing?

Desired output is, it should print the last event after 10 seconds(auto\_flush\_interval =\> 10). Instead it is throwing \_grokparsefailure after reaching the last event. For example, if there are 10 events in the file(this is a log file which continuously grows), it's printing 9 events normally, but throwing \_grokparsefailure continuously(it never ends)

---

<div class="post-metadata">

### Author: ![amruth](https://avatars.discourse-cdn.com/v4/letter/a/43a26b/32.png) [@amruth](https://discuss.elastic.co/u/amruth)
#### Post date: [September 29, 2017, 8:23pm UTC](https://discuss.elastic.co/t/auto-flush-interval-in-multiline-codec-plugin-errors-out/99345/8 "2017-09-29T20:23:46Z")

</div>

Hi, This is crucial now. Any help is highly appreciated. Can someone please help me solve this issue?

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [October 27, 2017, 8:24pm UTC](https://discuss.elastic.co/t/auto-flush-interval-in-multiline-codec-plugin-errors-out/99345/9 "2017-10-27T20:24:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
