# Can long grok filter line be extended into multiple lines?

**URL:** <https://discuss.elastic.co/t/can-long-grok-filter-line-be-extended-into-multiple-lines/54880>\
**Category:** Logstash\
**Created:** [July 7, 2016, 12:17am UTC](https://discuss.elastic.co/t/can-long-grok-filter-line-be-extended-into-multiple-lines/54880 "2016-07-07T00:17:42Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![zoplex](https://avatars.discourse-cdn.com/v4/letter/z/bc8723/32.png) [@zoplex](https://discuss.elastic.co/u/zoplex)\
**Post date:** [July 7, 2016, 12:17am UTC](https://discuss.elastic.co/t/can-long-grok-filter-line-be-extended-into-multiple-lines/54880/1 "2016-07-07T00:17:42Z")

</div>

- is there a continuation syntax - some of my filters are stretching beyond 150 characters - would be nice if that could be extended into second line ...

Thanks,

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 7, 2016, 12:23am UTC](https://discuss.elastic.co/t/can-long-grok-filter-line-be-extended-into-multiple-lines/54880/2 "2016-07-07T00:23:29Z")

</div>

Have you seen [https://www.elastic.co/guide/en/logstash/current/plugins-codecs-multiline.html](https://www.elastic.co/guide/en/logstash/current/plugins-codecs-multiline.html)?

---

<div class="post-metadata">

**Author:** ![zoplex](https://avatars.discourse-cdn.com/v4/letter/z/bc8723/32.png) [@zoplex](https://discuss.elastic.co/u/zoplex)\
**Post date:** [July 7, 2016, 12:30am UTC](https://discuss.elastic.co/t/can-long-grok-filter-line-be-extended-into-multiple-lines/54880/3 "2016-07-07T00:30:35Z")

</div>

yes I did - that merges multiple lines from the input file into one event ... I would like to break long lines from logstash.conf - like very long grok filter line, can it be folded into multiple filter line - talking about the grok code / - message filter itself, not the data ... Example:

match =\> ["message" =\> "%{TIMESTAMP\_ISO8601:zxk\_mysql\_timestamp} %{NUMBER:zxk\_num\_xxx} [%{MYSQLWARNING2:zxk\_mysql\_msgtype}] %{GREEDYDATA:zxk\_warning\_rest}",

Could I break the line after say 100 characters and extended it into second line:

match =\> [ "message" =\> "%{TIMESTAMP\_ISO8601:ses\_mysql\_timestamp} %{NUMBER:ses\_num\_xxx} -  
[%{MYSQLWARNING2:ses\_mysql\_msgtype}] %{GREEDYDATA:ses\_warning\_rest}",

using some kind of continuation character - I used '-' in the example here ... but that did not work in logstash

could not find it in the syntax anywhere ...

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 7, 2016, 12:31am UTC](https://discuss.elastic.co/t/can-long-grok-filter-line-be-extended-into-multiple-lines/54880/4 "2016-07-07T00:31:48Z")

</div>

Oh, right.

No you cannot.

---

<div class="post-metadata">

**Author:** ![zoplex](https://avatars.discourse-cdn.com/v4/letter/z/bc8723/32.png) [@zoplex](https://discuss.elastic.co/u/zoplex)\
**Post date:** [July 7, 2016, 12:33am UTC](https://discuss.elastic.co/t/can-long-grok-filter-line-be-extended-into-multiple-lines/54880/5 "2016-07-07T00:33:35Z")

</div>

ok - thanks - too bad though - filters easily get very long and I need 30 inch monitor for those ...

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 7, 2016, 12:45am UTC](https://discuss.elastic.co/t/can-long-grok-filter-line-be-extended-into-multiple-lines/54880/6 "2016-07-07T00:45:47Z")

</div>

You can do something like this if you have multiple patterns;

```auto
filter {
  grok { match => { "message" => ["Duration: %{NUMBER:duration}", "Speed: %{NUMBER:speed}"],
                                 ["Something: %{NUMBER:duration}", "Somethingelse: %{NUMBER:speed}"],
                                 ["Foo: %{NUMBER:duration}", "Bar: %{NUMBER:speed}"]
                                 }
  }
}

```

---

<div class="post-metadata">

**Author:** ![zoplex](https://avatars.discourse-cdn.com/v4/letter/z/bc8723/32.png) [@zoplex](https://discuss.elastic.co/u/zoplex)\
**Post date:** [July 7, 2016, 12:50am UTC](https://discuss.elastic.co/t/can-long-grok-filter-line-be-extended-into-multiple-lines/54880/7 "2016-07-07T00:50:47Z")

</div>

true - but if any one pattern out of those three is 200 characters long then the editor wraps the line ... to the far left ... not very readable ...

I think I can define my own patterns that cover multiple tokens into one - then store that into patterns file - but makes it less readable since one needs to look into the pattern file to see what the short pattern is ... that will make match line short but at the cost of having to look into pattern file ... not too bad - just though that there may be a way syntactically to continue one line into the next ...

---

<div class="post-metadata">

**Author:** ![zoplex](https://avatars.discourse-cdn.com/v4/letter/z/bc8723/32.png) [@zoplex](https://discuss.elastic.co/u/zoplex)\
**Post date:** [July 7, 2016, 12:51am UTC](https://discuss.elastic.co/t/can-long-grok-filter-line-be-extended-into-multiple-lines/54880/8 "2016-07-07T00:51:23Z")

</div>

.. I have filter lines that break the line into 10+ fields ... those get very long ...

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:49am UTC](https://discuss.elastic.co/t/can-long-grok-filter-line-be-extended-into-multiple-lines/54880/9 "2017-07-06T04:49:13Z")

</div>


