# Codec multiline with redis

**URL:** <https://discuss.elastic.co/t/codec-multiline-with-redis/66827>\
**Category:** Logstash\
**Created:** [November 22, 2016, 8:57am UTC](https://discuss.elastic.co/t/codec-multiline-with-redis/66827 "2016-11-22T08:57:52Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![nick76](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nick76/32/6697_2.png) [@nick76](https://discuss.elastic.co/u/nick76)\
**Post date:** [November 22, 2016, 8:57am UTC](https://discuss.elastic.co/t/codec-multiline-with-redis/66827/1 "2016-11-22T08:57:52Z")

</div>

Hello all,  
in my setup I had to use the redis aggregator:  
varnish+apache+tomcat (filebeat) --\> redis \<-- |fw|-- logstash 5.0  
in this setup I got different log types from different sources that need to be parsed correctly.  
the main problem is related to java logs that provides different type of log format (catalina.out, tomcat.log, ...) that often have multiline setup.  
I tried using the multiline filter but I got:  
`reason=>"Couldn't find any filter plugin named 'multiline'. Are you sure this is correct? Trying to load the multiline filter plugin resulted in this error: LoadError"`  
I think I've to use the codec-multiline, but, how can I configure multiline that comes from the same input (the redis server) that need to be treated differently?  
thank you very much  
best regards  
Nicola

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 22, 2016, 9:01am UTC](https://discuss.elastic.co/t/codec-multiline-with-redis/66827/2 "2016-11-22T09:01:59Z")

</div>

You should ideally assemble multi-line entries as close to the source as this process requires the events to arrive in sequence. It should therefore be done before putting it on any message queue. Filebeat [supports multi-line processing](https://www.elastic.co/guide/en/beats/filebeat/current/multiline-examples.html), so that is where I would recommend doing this processing.

---

<div class="post-metadata">

**Author:** ![nick76](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nick76/32/6697_2.png) [@nick76](https://discuss.elastic.co/u/nick76)\
**Post date:** [November 22, 2016, 9:55am UTC](https://discuss.elastic.co/t/codec-multiline-with-redis/66827/3 "2016-11-22T09:55:09Z")

</div>

Hi Christian,  
thank you very much for your reply. can I use the same pattern syntax both in filebeat as in logstash?  
best regards  
Nicola

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 27, 2016, 8:09pm UTC](https://discuss.elastic.co/t/codec-multiline-with-redis/66827/4 "2016-11-27T20:09:17Z")

</div>

> can I use the same pattern syntax both in filebeat as in logstash?

No. See the Filebeat documentation for details on what kind of patterns are allowed.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 25, 2016, 8:09pm UTC](https://discuss.elastic.co/t/codec-multiline-with-redis/66827/5 "2016-12-25T20:09:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
