# Error when filter multiline of rabbitmq log

**URL:** <https://discuss.elastic.co/t/error-when-filter-multiline-of-rabbitmq-log/103654>\
**Category:** Logstash\
**Created:** [October 12, 2017, 6:55am UTC](https://discuss.elastic.co/t/error-when-filter-multiline-of-rabbitmq-log/103654 "2017-10-12T06:55:39Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![vuxuanlai](https://avatars.discourse-cdn.com/v4/letter/v/ecd19e/32.png) [@vuxuanlai](https://discuss.elastic.co/u/vuxuanlai)\
**Post date:** [October 12, 2017, 6:55am UTC](https://discuss.elastic.co/t/error-when-filter-multiline-of-rabbitmq-log/103654/1 "2017-10-12T06:55:39Z")

</div>

When i parse log from rabbitmq, i got the error as below:  
`

> [2017-10-12T04:01:18,006][ERROR][logstash.agent] Cannot create pipeline {:reason=\>"The setting `type` in plugin `multiline` is obsolete and is no longer available. You can achieve this same behavior with the new conditionals, like: `if [type] == \"sometype\" { multiline { ... } }`. If you have any questions about this, you are invited to visit [Logstash - Discuss the Elastic Stack](https://discuss.elastic.co/c/logstash) and ask."}

`

The following is my config:

```
input {
	file {
		type => "rabbit"
		path => "/home/ubuntu/logstash-5.6.2/rabbitmq.log"
	}
}
filter {
	multiline{
		type => "rabbit"
		pattern => "^="
		negate => true
		what => "previous"
	}
	grok {
		type => "rabbit"
		patterns_dir => "patterns"
		pattern => "^=%{WORD:report_type} REPORT=+ %{RABBIT_TIME:time_text} ===.*$"
	}
	mutate {
		type => "rabbit"
		add_field => ["message", "%{@message}"]
	}
	mutate {
		gsub => [
		  "message", "^=[A-Za-z0-9: =-]+=\n", "",
		  # interpret message header text as "severity"
		  "report_type", "INFO", "1",
		  "report_type", "WARNING", "3",
		  "report_type", "ERROR", "4",
		  "report_type", "CRASH", "5",
		  "report_type", "SUPERVISOR", "5"
		]
	}
	
}
output {
	stdout { codec => rubydebug }
}

```

* * *

Could someone help me in this case?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [October 12, 2017, 7:00am UTC](https://discuss.elastic.co/t/error-when-filter-multiline-of-rabbitmq-log/103654/2 "2017-10-12T07:00:51Z")

</div>

The multiline filter plugin has been deprecated. Instead use the [multiline codec](https://www.elastic.co/guide/en/logstash/current/plugins-codecs-multiline.html) with your file input plugin.

---

<div class="post-metadata">

**Author:** ![vuxuanlai](https://avatars.discourse-cdn.com/v4/letter/v/ecd19e/32.png) [@vuxuanlai](https://discuss.elastic.co/u/vuxuanlai)\
**Post date:** [October 12, 2017, 7:04am UTC](https://discuss.elastic.co/t/error-when-filter-multiline-of-rabbitmq-log/103654/3 "2017-10-12T07:04:21Z")

</div>

So how can i use logstash filter to parse rabbitmq log?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [October 12, 2017, 7:06am UTC](https://discuss.elastic.co/t/error-when-filter-multiline-of-rabbitmq-log/103654/4 "2017-10-12T07:06:00Z")

</div>

Specify a multiline codec for the file input plugin and remove the multiline filter. You should be able to keep the rest the same, although I do not understand why you are specifying `type => "rabbit"` for the filter plugins.

---

<div class="post-metadata">

**Author:** ![vuxuanlai](https://avatars.discourse-cdn.com/v4/letter/v/ecd19e/32.png) [@vuxuanlai](https://discuss.elastic.co/u/vuxuanlai)\
**Post date:** [October 12, 2017, 7:07am UTC](https://discuss.elastic.co/t/error-when-filter-multiline-of-rabbitmq-log/103654/5 "2017-10-12T07:07:59Z")

</div>

I edited as your recommend. The following is my edition:

```
input {
	file {
		type => "rabbit"
		path => "/home/ubuntu/logstash-5.6.2/rabbitmq.log"
		codec => multiline{
			pattern => "^="
			negate => true
			what => "previous"
		}
	}
}
filter {

grok {
	type => "rabbit"
	patterns_dir => "patterns"
	pattern => "^=%{WORD:report_type} REPORT=+ %{RABBIT_TIME:time_text} ===.*$"
}
mutate {
	type => "rabbit"
	add_field => ["message", "%{@message}"]
}
mutate {
	gsub => [
	  "message", "^=[A-Za-z0-9: =-]+=\n", "",
	  # interpret message header text as "severity"
	  "report_type", "INFO", "1",
	  "report_type", "WARNING", "3",
	  "report_type", "ERROR", "4",
	  "report_type", "CRASH", "5",
	  "report_type", "SUPERVISOR", "5"
	]
}

}
output {
	stdout { codec => rubydebug }
}

```

* * *

I got the error:  
[2017-10-12T07:03:20,501][ERROR][logstash.agent] Cannot create pipeline {:reason=\>"The setting `type` in plugin `grok` is obsolete and is no longer available. You can achieve this same behavior with the new conditionals, like: `if [type] == \"sometype\" { grok { ... } }`. If you have any questions about this, you are invited to visit [https://discuss.elastic.co/c/logstash](https://discuss.elastic.co/c/logstash) and ask."}

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [October 12, 2017, 7:10am UTC](https://discuss.elastic.co/t/error-when-filter-multiline-of-rabbitmq-log/103654/6 "2017-10-12T07:10:26Z")

</div>

> [@vuxuanlai](#):
>
> type =\> "rabbit"

You should remove this from your plugin config as I do not think it is supported any longer. You can see exactly which configuration parameters that are supported in the documentation.

---

<div class="post-metadata">

**Author:** ![vuxuanlai](https://avatars.discourse-cdn.com/v4/letter/v/ecd19e/32.png) [@vuxuanlai](https://discuss.elastic.co/u/vuxuanlai)\
**Post date:** [October 12, 2017, 7:17am UTC](https://discuss.elastic.co/t/error-when-filter-multiline-of-rabbitmq-log/103654/7 "2017-10-12T07:17:58Z")

</div>

I changed my config to your recommend, so it still got error. Could you give me some suggests or examples to parse rabbitmq log using logstash filter?  
Thank you.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [October 12, 2017, 7:19am UTC](https://discuss.elastic.co/t/error-when-filter-multiline-of-rabbitmq-log/103654/8 "2017-10-12T07:19:06Z")

</div>

What does the config look like now? What error are you getting?

---

<div class="post-metadata">

**Author:** ![vuxuanlai](https://avatars.discourse-cdn.com/v4/letter/v/ecd19e/32.png) [@vuxuanlai](https://discuss.elastic.co/u/vuxuanlai)\
**Post date:** [October 12, 2017, 7:22am UTC](https://discuss.elastic.co/t/error-when-filter-multiline-of-rabbitmq-log/103654/9 "2017-10-12T07:22:28Z")

</div>

```
input {
	file {
		path => "/home/ubuntu/logstash-5.6.2/rabbitmq.log"
		codec => multiline{
			pattern => "^="
			negate => true
			what => "previous"
		}
	}
}
filter {
	
	grok {
		patterns_dir => "patterns"
		match => {"message" => "^=%{WORD:report_type} REPORT=+ %{RABBIT_TIME:time_text} ===.*$"}
	}
	mutate {
		add_field => ["message", "%{@message}"]
	}
	mutate {
		gsub => [
		  "message", "^=[A-Za-z0-9: =-]+=\n", "",
		  # interpret message header text as "severity"
		  "report_type", "INFO", "1",
		  "report_type", "WARNING", "3",
		  "report_type", "ERROR", "4",
		  "report_type", "CRASH", "5",
		  "report_type", "SUPERVISOR", "5"
		]
	}
	
}
output {
	stdout { codec => rubydebug }
}

```

The error:  
[2017-10-12T07:20:53,132][ERROR][logstash.agent] Pipeline aborted due to error {:exception=\>#\<Grok::PatternError: pattern %{RABBIT\_TIME:time\_text} not defined\>, :backtrace=\>["/home/ubuntu/logstash-5.6.2/vendor/bundle/jruby/1.9/gems/jls-grok-0.11.4/lib/grok-pure.rb:123:in `compile'",...........

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 12, 2017, 7:28am UTC](https://discuss.elastic.co/t/error-when-filter-multiline-of-rabbitmq-log/103654/10 "2017-10-12T07:28:55Z")

</div>

As the error message says it's not able to find a definition of your RABBIT\_TIME pattern. I suggest you use the absolute path in the grok filter's `patterns_dir` option.

---

<div class="post-metadata">

**Author:** ![vuxuanlai](https://avatars.discourse-cdn.com/v4/letter/v/ecd19e/32.png) [@vuxuanlai](https://discuss.elastic.co/u/vuxuanlai)\
**Post date:** [October 12, 2017, 7:40am UTC](https://discuss.elastic.co/t/error-when-filter-multiline-of-rabbitmq-log/103654/11 "2017-10-12T07:40:00Z")

</div>

Thanks magnusbaeck, there are no error when i change config as recommend. However, i can't get any result on screen when read log from file as input.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 9, 2017, 7:40am UTC](https://discuss.elastic.co/t/error-when-filter-multiline-of-rabbitmq-log/103654/12 "2017-11-09T07:40:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
