# Drop Lines before multiline codec

**URL:** <https://discuss.elastic.co/t/drop-lines-before-multiline-codec/91500>\
**Category:** Logstash\
**Created:** [July 1, 2017, 1:17am UTC](https://discuss.elastic.co/t/drop-lines-before-multiline-codec/91500 "2017-07-01T01:17:35Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![ssstarquin](https://avatars.discourse-cdn.com/v4/letter/s/e480ec/32.png) [@ssstarquin](https://discuss.elastic.co/u/ssstarquin)\
**Post date:** [July 1, 2017, 1:17am UTC](https://discuss.elastic.co/t/drop-lines-before-multiline-codec/91500/1 "2017-07-01T01:17:35Z")

</div>

I am parsing multiple files using the multiline codec .  
Using the following to convert the file contents into one big string and then extract patterns i need from that string.

```
input {
    file {
            path => "/logstash_test/*.*"
            start_position => "beginning"
            codec => multiline {
                      pattern => "^ENDOFFILE$"
                      negate => "true"
                      what => "previous"
                    }
            sincedb_path => "/dev/null"
     }
}
filter{
some groks which works on the above big line .
}

```

- Is there any way to drop lines from the log before of during the multiline codec is running . ie . if i have a file containing following text .

How can i omit all lines starting with e[1;30m[14:52:49] while also merging the remaining lines using multiline. i need to negate some lines and retain others during multiline processing.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 3, 2017, 8:04pm UTC](https://discuss.elastic.co/t/drop-lines-before-multiline-codec/91500/2 "2017-07-03T20:04:24Z")

</div>

I don't think there's a way to do that, sorry.

---

<div class="post-metadata">

**Author:** ![ssstarquin](https://avatars.discourse-cdn.com/v4/letter/s/e480ec/32.png) [@ssstarquin](https://discuss.elastic.co/u/ssstarquin)\
**Post date:** [July 5, 2017, 4:58am UTC](https://discuss.elastic.co/t/drop-lines-before-multiline-codec/91500/3 "2017-07-05T04:58:41Z")

</div>

Can i create a custom codec plugin that does this using the following

I was looking into

- [https://www.elastic.co/guide/en/logstash/current/\_how\_to\_write\_a\_logstash\_codec\_plugin.html](https://www.elastic.co/guide/en/logstash/current/_how_to_write_a_logstash_codec_plugin.html)
- [https://github.com/logstash-plugins/logstash-codec-multiline](https://github.com/logstash-plugins/logstash-codec-multiline)

Could you please provide some guidelines regarding regular expression to use ?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 5, 2017, 5:07am UTC](https://discuss.elastic.co/t/drop-lines-before-multiline-codec/91500/4 "2017-07-05T05:07:24Z")

</div>

Sure, making a custom codec is always possible. You could clone the multiline codec and just add a few lines of code to skip the unwanted lines.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 2, 2017, 5:07am UTC](https://discuss.elastic.co/t/drop-lines-before-multiline-codec/91500/5 "2017-08-02T05:07:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
