# Codec in gelf input plugin not working

**URL:** <https://discuss.elastic.co/t/codec-in-gelf-input-plugin-not-working/308017>\
**Category:** Logstash\
**Created:** [June 23, 2022, 1:33pm UTC](https://discuss.elastic.co/t/codec-in-gelf-input-plugin-not-working/308017 "2022-06-23T13:33:55Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![smtp\_server](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/smtp_server/32/102266_2.png) [@smtp\_server](https://discuss.elastic.co/u/smtp_server)\
**Post date:** [June 23, 2022, 1:33pm UTC](https://discuss.elastic.co/t/codec-in-gelf-input-plugin-not-working/308017/1 "2022-06-23T13:33:55Z")

</div>

I'm trying to use codec for logs coming from gelf driver of another container to aggregate multiline logs but they are turning into events for each line in message, So multiline is not working at all.

```auto
input{
  gelf{
    port => 514
    
    codec => multiline {
        	     
          pattern => "^%{YEAR}-%{MONTHNUM}-%{MONTHDAY}"
          negate => "true"
          what => "previous"
	}
  }
}

```

What am I doing wrong as multiline doesn't seem to be working for any type of pattern for gelf?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [June 23, 2022, 1:49pm UTC](https://discuss.elastic.co/t/codec-in-gelf-input-plugin-not-working/308017/2 "2022-06-23T13:49:15Z")

</div>

Please share examples of the messages you are receiving and also an example of your multiline event.

---

<div class="post-metadata">

**Author:** ![smtp\_server](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/smtp_server/32/102266_2.png) [@smtp\_server](https://discuss.elastic.co/u/smtp_server)\
**Post date:** [June 23, 2022, 2:04pm UTC](https://discuss.elastic.co/t/codec-in-gelf-input-plugin-not-working/308017/3 "2022-06-23T14:04:50Z")

</div>

> 2022-06-23 13:53:19.820 WARN [fmpGateway,9ec322a35a8ee222,9ec322a35a8ee222,false] 1 --- [XNIO-1 task-1] o.s.c.n.zuul.web.ZuulHandlerMapping : No routes found from RouteLocator  
> In SecurityConfiguration : UserAuthoritiesMapper:: [ROLE\_USER, SCOPE\_address, SCOPE\_email, SCOPE\_jhipster, SCOPE\_microprofile-jwt, SCOPE\_offline\_access, SCOPE\_openid, SCOPE\_phone, SCOPE\_profile]  
> In SecurityConfiguration : UserAuthoritiesMapper:: [ROLE\_USER, ROLE\_ADMIN]  
> \*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*@@@authorities::[ROLE\_USER, SCOPE\_address, SCOPE\_email, SCOPE\_jhipster, SCOPE\_microprofile-jwt, SCOPE\_offline\_access, SCOPE\_openid, SCOPE\_phone, SCOPE\_profile]  
> \*\*\*\*\*\*\*\*\*\*\*\*\*\*\*attributes:::{sub=4c973896-5761-41fc-8217-07c5d13a004b, email\_verified=true, address={}, roles=[ROLE\_USER, offline\_access, ROLE\_ADMIN, uma\_authorization], iss=[http://keycloak:9080/auth/realms/jhipster](http://keycloak:9080/auth/realms/jhipster), groups=["ROLE\_USER","offline\_access","ROLE\_ADMIN","uma\_authorization"], typ=ID, preferred\_username=admin, given\_name=Admin, nonce=mZhSheicHPK02ZB\_Brxruc07HCKxIxCMX88S3aTiHHg, aud=[web\_app], acr=1, upn=admin, nbf=Thu Jan 01 00:00:00 GMT 1970, azp=web\_app, auth\_time=2022-06-23T13:55:51Z, name=Admin Administrator, exp=2022-06-23T14:00:51Z, session\_state=33c30859-9e3b-4f89-9f5a-5433fa313140, family\_name=Administrator, iat=2022-06-23T13:55:51Z, email=admin@localhost, jti=ef9df142-9abd-40cb-b59c-46982309f3b2}  
> \*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*attributes keys:: [sub, email\_verified, address, roles, iss, groups, typ, preferred\_username, given\_name, nonce, aud, acr, upn, nbf, azp, auth\_time, name, exp, session\_state, family\_name, iat, email, jti]  
> %%%%%%%%authority%%%%ROLE\_USER  
> %%%%%%%%authority%%%%SCOPE\_address  
> %%%%%%%%authority%%%%SCOPE\_email  
> %%%%%%%%authority%%%%SCOPE\_jhipster  
> %%%%%%%%authority%%%%SCOPE\_microprofile-jwt

> {  
> "hostname" =\> "aman-HP-ProBook-440-G8-Notebook-PC",  
> "@timestamp" =\> 2022-06-23T13:55:51.622Z,  
> "command" =\> "./entrypoint.sh",  
> "message" =\> "In SecurityConfiguration : UserAuthoritiesMapper:: [ROLE\_USER, SCOPE\_address, SCOPE\_email, SCOPE\_jhipster, SCOPE\_microprofile-jwt, SCOPE\_offline\_access, SCOPE\_openid, SCOPE\_phone, SCOPE\_profile]",  
> "image\_id" =\> "sha256:d3f1e9dc3eca3a7d75eb8cf2b89dfa58e2d533ec9f38e41f81e7714ef708736a",  
> "tag" =\> "71239affab45",  
> "created" =\> "2022-06-19T17:38:28.723336637Z",  
> "image\_name" =\> "api:latest",  
> "container\_id" =\> "71239affab45e8ceebab404c3593cfdd891021ab440b34c57ba07f4e57de807e",  
> "data" =\> "{"log":"In SecurityConfiguration : UserAuthoritiesMapper:: [ROLE\_USER, SCOPE\_address, SCOPE\_email, SCOPE\_jhipster, SCOPE\_microprofile-jwt, SCOPE\_offline\_access, SCOPE\_openid, SCOPE\_phone, SCOPE\_profile]"}",  
> "log" =\> "In SecurityConfiguration : UserAuthoritiesMapper:: [ROLE\_USER, SCOPE\_address, SCOPE\_email, SCOPE\_jhipster, SCOPE\_microprofile-jwt, SCOPE\_offline\_access, SCOPE\_openid, SCOPE\_phone, SCOPE\_profile]",  
> "hash" =\> "SharedKey 90c5ca8f-3f89-490e-9a54-4781f4b5ebd1:erEMBDMGTOHxkuyUURER4/mculSANfmCjBNDBbWmgYs=",  
> "level" =\> 6,  
> "@version" =\> "1",  
> "container\_name" =\> "docker\_fmpgateway-app\_1",  
> "source\_host" =\> "172.18.0.1",  
> "version" =\> "1.1",  
> "x-ms-date" =\> "Thu, 23 Jun 2022 13:55:51 GMT",  
> "content-length" =\> "204",  
> "string" =\> "POST\n204\napplication/json\nx-ms-date:Thu, 23 Jun 2022 13:55:51 GMT\n/api/logs"  
> }

> {  
> "hostname" =\> "aman-HP-ProBook-440-G8-Notebook-PC",  
> "@timestamp" =\> 2022-06-23T13:55:51.624Z,  
> "command" =\> "./entrypoint.sh",  
> "message" =\> "In SecurityConfiguration : UserAuthoritiesMapper:: [ROLE\_USER, ROLE\_ADMIN]",  
> "image\_id" =\> "sha256:d3f1e9dc3eca3a7d75eb8cf2b89dfa58e2d533ec9f38e41f81e7714ef708736a",  
> "tag" =\> "71239affab45",  
> "created" =\> "2022-06-19T17:38:28.723336637Z",  
> "image\_name" =\> "api:latest",  
> "container\_id" =\> "71239affab45e8ceebab404c3593cfdd891021ab440b34c57ba07f4e57de807e",  
> "data" =\> "{"log":"In SecurityConfiguration : UserAuthoritiesMapper:: [ROLE\_USER, ROLE\_ADMIN]"}",  
> "log" =\> "In SecurityConfiguration : UserAuthoritiesMapper:: [ROLE\_USER, ROLE\_ADMIN]",  
> "hash" =\> "SharedKey 90c5ca8f-3f89-490e-9a54-4781f4b5ebd1:PHRlpCWzGk//+MWER0AmxvpUXDDBFI/4ZcaipLOAUsE=",  
> "level" =\> 6,  
> "@version" =\> "1",  
> "container\_name" =\> "docker\_fmpgateway-app\_1",  
> "source\_host" =\> "172.18.0.1",  
> "version" =\> "1.1",  
> "x-ms-date" =\> "Thu, 23 Jun 2022 13:55:51 GMT",  
> "content-length" =\> "84",  
> "string" =\> "POST\n84\napplication/json\nx-ms-date:Thu, 23 Jun 2022 13:55:51 GMT\n/api/logs"  
> }

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 23, 2022, 3:19pm UTC](https://discuss.elastic.co/t/codec-in-gelf-input-plugin-not-working/308017/4 "2022-06-23T15:19:26Z")

</div>

> [@smtp\_server](#):
>
> What am I doing wrong as multiline doesn't seem to be working for any type of pattern for gelf?

An input has to have a codec option, but it does not have to use it. By my reading the [gelf input](https://github.com/logstash-plugins/logstash-input-gelf/blob/main/lib/logstash/inputs/gelf.rb) ignores it. GELF messages are always JSON encoded objects, so the plugin parses them that way.

---

<div class="post-metadata">

**Author:** ![smtp\_server](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/smtp_server/32/102266_2.png) [@smtp\_server](https://discuss.elastic.co/u/smtp_server)\
**Post date:** [June 23, 2022, 3:29pm UTC](https://discuss.elastic.co/t/codec-in-gelf-input-plugin-not-working/308017/5 "2022-06-23T15:29:28Z")

</div>

What could be the way to do this? if I use udp input plugin, it still doesn't work and render bytes.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 23, 2022, 3:37pm UTC](https://discuss.elastic.co/t/codec-in-gelf-input-plugin-not-working/308017/6 "2022-06-23T15:37:03Z")

</div>

You might be able to do it using the deprecated [multiline filter](https://www.elastic.co/guide/en/logstash/8.2/plugins-filters-multiline.html). Source [here](https://github.com/logstash-plugins/logstash-filter-multiline/blob/main/lib/logstash/filters/multiline.rb).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 21, 2022, 3:37pm UTC](https://discuss.elastic.co/t/codec-in-gelf-input-plugin-not-working/308017/7 "2022-07-21T15:37:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
