# Equivalent of 'stream\_identity' for multiline codec

**URL:** <https://discuss.elastic.co/t/equivalent-of-stream-identity-for-multiline-codec/45785>\
**Category:** Logstash\
**Created:** [March 30, 2016, 11:54am UTC](https://discuss.elastic.co/t/equivalent-of-stream-identity-for-multiline-codec/45785 "2016-03-30T11:54:11Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![jpry](https://avatars.discourse-cdn.com/v4/letter/j/ecae2f/32.png) [@jpry](https://discuss.elastic.co/u/jpry)\
**Post date:** [March 30, 2016, 11:54am UTC](https://discuss.elastic.co/t/equivalent-of-stream-identity-for-multiline-codec/45785/1 "2016-03-30T11:54:12Z")

</div>

Hello,

All is in the title. Is there an equivalent for 'stream\_identity' property of the multiline filter in multiline codec? How to merge interlaced log lines based on their dynamic identifier using multiline codec in a multi-threads environment?

I have the following log lines:

```
Feb 16 17:29:04 notice apd[5515]: 01490010:5: 1ec2b273:Username 'cjones'

Feb 16 17:29:04 warning apd[5515]: 01490106:4: 1ec2b273: AD module: authentication with 'cjones' failed: Preauthentication failed, principal name: cjones@GEEKO.COM. Invalid user credentials. (-1765328360)

Feb 16 17:10:04 notice apd[5515]: 01490010:5: d8b5a591: Username 'gbridget'

Feb 16 17:10:04 err apd[5515]: 01490107:3: d8b5a591: AD module: authentication with 'gbridget' failed: Clients credentials have been revoked, principal name: gbridget@GEEKO.COM. User account is locked (-1765328366)

Feb 16 17:29:04 notice apd[5515]: 01490005:5: 1ec2b273: Following rule 'fallback' from item 'AD Auth' to ending 'Deny'

Feb 16 17:29:04 notice apd[5515]: 01490102:5: 1ec2b273: Access policy result: Logon_Deny

```

I'd like to join them like this:

1st event with id:1ec2b273:

```
Feb 16 17:29:04 notice apd[5515]: 01490010:5: 1ec2b273:Username 'cjones'

Feb 16 17:29:04 warning apd[5515]: 01490106:4: 1ec2b273: AD module: authentication with 'cjones' failed: Preauthentication failed, principal name: cjones@GEEKO.COM. Invalid user credentials. (-1765328360)

Feb 16 17:29:04 notice apd[5515]: 01490005:5: 1ec2b273: Following rule 'fallback' from item 'AD Auth' to ending 'Deny'

Feb 16 17:29:04 notice apd[5515]: 01490102:5: 1ec2b273: Access policy result: Logon_Deny

```

2nd event with id:d8b5a591:

```
Feb 16 17:10:04 notice apd[5515]: 01490010:5: d8b5a591: Username 'gbridget'

Feb 16 17:10:04 err apd[5515]: 01490107:3: d8b5a591: AD module: authentication with 'gbridget' failed: Clients credentials have been revoked, principal name: gbridget@GEEKO.COM. User account is locked (-1765328366)

```

I'd like to gather these related lines so that I could relate a username to its email address for instance. If stream\_identity option is no more available, Is there a way to query multiple elasticsearch documents to perform this action?

Thanks in advance

---

<div class="post-metadata">

**Author:** ![jpry](https://avatars.discourse-cdn.com/v4/letter/j/ecae2f/32.png) [@jpry](https://discuss.elastic.co/u/jpry)\
**Post date:** [March 31, 2016, 2:26pm UTC](https://discuss.elastic.co/t/equivalent-of-stream-identity-for-multiline-codec/45785/2 "2016-03-31T14:26:21Z")

</div>

Up 🙂

---

<div class="post-metadata">

**Author:** ![jpry](https://avatars.discourse-cdn.com/v4/letter/j/ecae2f/32.png) [@jpry](https://discuss.elastic.co/u/jpry)\
**Post date:** [April 6, 2016, 8:23am UTC](https://discuss.elastic.co/t/equivalent-of-stream-identity-for-multiline-codec/45785/3 "2016-04-06T08:23:08Z")

</div>

Really this inspires noone?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:03am UTC](https://discuss.elastic.co/t/equivalent-of-stream-identity-for-multiline-codec/45785/4 "2017-07-06T05:03:37Z")

</div>


