# Does the multiline codec plugin in Logstash include newline characters in the output string?

**URL:** <https://discuss.elastic.co/t/does-the-multiline-codec-plugin-in-logstash-include-newline-characters-in-the-output-string/119278>\
**Category:** Logstash\
**Created:** [February 9, 2018, 5:11pm UTC](https://discuss.elastic.co/t/does-the-multiline-codec-plugin-in-logstash-include-newline-characters-in-the-output-string/119278 "2018-02-09T17:11:40Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![daved](https://avatars.discourse-cdn.com/v4/letter/d/bcef8e/32.png) [@daved](https://discuss.elastic.co/u/daved)\
**Post date:** [February 9, 2018, 5:11pm UTC](https://discuss.elastic.co/t/does-the-multiline-codec-plugin-in-logstash-include-newline-characters-in-the-output-string/119278/1 "2018-02-09T17:11:40Z")

</div>

I'm wondering if the multiline codec plugin in Logstash includes newlines in the output? I want to use regex on the output and this is important to understand in order to design my regex and have it perform well.

Looking at the documentation at [https://www.elastic.co/guide/en/logstash/current/plugins-codecs-multiline.html](https://www.elastic.co/guide/en/logstash/current/plugins-codecs-multiline.html) I don't see any mention of this. FWIW I think the behavior should be documented.

Thanks!

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 9, 2018, 5:27pm UTC](https://discuss.elastic.co/t/does-the-multiline-codec-plugin-in-logstash-include-newline-characters-in-the-output-string/119278/2 "2018-02-09T17:27:23Z")

</div>

Yes, it does. With this config

```
input{
        stdin{
                codec => multiline { 
                        pattern => "^}"
                        negate => true 
                        what => next 
                } 
        }
}
output { stdout { codec => rubydebug } }
```

and this input

```
{
}
{
}
```

the messages you get contain 1 newline

```
"message" => "{\n}",
          "tags" => [
        [0] "multiline"
    ],
```

---

<div class="post-metadata">

**Author:** ![daved](https://avatars.discourse-cdn.com/v4/letter/d/bcef8e/32.png) [@daved](https://discuss.elastic.co/u/daved)\
**Post date:** [February 9, 2018, 9:02pm UTC](https://discuss.elastic.co/t/does-the-multiline-codec-plugin-in-logstash-include-newline-characters-in-the-output-string/119278/3 "2018-02-09T21:02:35Z")

</div>

Awesome, thank you!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 9, 2018, 9:02pm UTC](https://discuss.elastic.co/t/does-the-multiline-codec-plugin-in-logstash-include-newline-characters-in-the-output-string/119278/4 "2018-03-09T21:02:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
