# Fluent codec and multline

**URL:** <https://discuss.elastic.co/t/fluent-codec-and-multline/212504>\
**Category:** Logstash\
**Created:** [December 19, 2019, 2:40pm UTC](https://discuss.elastic.co/t/fluent-codec-and-multline/212504 "2019-12-19T14:40:59Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![bquevat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bquevat/32/53368_2.png) [@bquevat](https://discuss.elastic.co/u/bquevat)\
**Post date:** [December 19, 2019, 2:40pm UTC](https://discuss.elastic.co/t/fluent-codec-and-multline/212504/1 "2019-12-19T14:40:59Z")

</div>

Hello,

I use the fluent codec in my input.  
It receives logs from Java applications and I would like to make Java stack trace into a single event.  
This can be done with the multiline plugin.  
How can I benefit from the functionnalities of both fluent and multiline codec?

My configuration below:

> input {  
> tcp{  
> port =\> 9532  
> codec =\> fluent  
> }  
> }
> 
> filter {
> 
> grok {  
> # Parsing des logs Tomcat HTTP  
> match =\> { "message" =\> [  
> "%{IP} - - [%{HTTPDATE}] "%{NOTSPACE:verb} %{NOTSPACE:request} HTTP/%{NUMBER:httpversion}" %{INT:code} %{INT:size} %{INT:time}",  
> "%{TIMESTAMP\_ISO8601:timestamp}\s+%{LOGLEVEL:severity}\s+[%{DATA:service},%{DATA:trace},%{DATA:span},%{DATA:exportable}]\s+%{DATA id}\s+---\s+[%{DATA:thread}]\s+%{DATA:class}\s+:\s+%{GREEDYDATA:logMessage}"  
> ]}  
> }
> 
> date {  
> match =\> ["timestamp" , "YY-MM-dd HH:mm:ss.SSS"]  
> }
> 
> }
> 
> output {  
> elasticsearch {  
> user =\> "logstash"  
> password =\> "xxxxx"  
> hosts =\> ["xxxxx:9632"]  
> index =\> "logstash-tap2use-%{+YYYY.MM.dd}"  
> document\_type =\> "logs"  
> }  
> }

Thanks for your help.

---

<div class="post-metadata">

**Author:** ![bquevat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bquevat/32/53368_2.png) [@bquevat](https://discuss.elastic.co/u/bquevat)\
**Post date:** [January 9, 2020, 2:42pm UTC](https://discuss.elastic.co/t/fluent-codec-and-multline/212504/2 "2020-01-09T14:42:01Z")

</div>

Hello,  
I'm trying to solve this issue with 2 pipelines.  
The input of the first pipeline will have a fluent codec. The Input of the second pipeline will have a multiline codec.  
Can someone confirm me that the multiline codec can be used with a pipeline input (as shown below)?

input {  
pipeline {  
address =\> myVirtualAddress  
codec =\> multiline {  
pattern =\> ".\*at"  
what =\> "previous"  
}  
}  
}

Thanks,  
Best regards,  
Benoît

---

<div class="post-metadata">

**Author:** ![bquevat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bquevat/32/53368_2.png) [@bquevat](https://discuss.elastic.co/u/bquevat)\
**Post date:** [January 14, 2020, 1:52pm UTC](https://discuss.elastic.co/t/fluent-codec-and-multline/212504/3 "2020-01-14T13:52:06Z")

</div>

Any idea on this issue?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 11, 2020, 1:52pm UTC](https://discuss.elastic.co/t/fluent-codec-and-multline/212504/4 "2020-02-11T13:52:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
