# Forwarding the field to the next event

**URL:** <https://discuss.elastic.co/t/forwarding-the-field-to-the-next-event/128504>\
**Category:** Logstash\
**Created:** [April 18, 2018, 10:04am UTC](https://discuss.elastic.co/t/forwarding-the-field-to-the-next-event/128504 "2018-04-18T10:04:53Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![MateuszB](https://avatars.discourse-cdn.com/v4/letter/m/d07c76/32.png) [@MateuszB](https://discuss.elastic.co/u/MateuszB)\
**Post date:** [April 18, 2018, 10:04am UTC](https://discuss.elastic.co/t/forwarding-the-field-to-the-next-event/128504/1 "2018-04-18T10:04:54Z")

</div>

Is it possible to pass the field to the next event.  
My log is multi-line:

> root: 192.168.1.10|unknown (66/tcp)|92567|Low|description|  
> root: 192.168.1.10|unknown (26/tcp)|92567|Low|description|  
> root: 192.168.1.10|unknown (56/tcp)|92567|Low|description|

In the field I will pass the number of occurrences of the word 'low'

my grok config:

> grok { match =\> ["message", "%{IPV4:host\_ip}|%{DATA:protokol\_port}|%{NUMBER:nessus\_id}|%{WORD:threatlvl}|%{DATA:description}|"] }

Unfortunately, each line of the log is parsed as a separate event and I can not pass the field

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 16, 2018, 10:05am UTC](https://discuss.elastic.co/t/forwarding-the-field-to-the-next-event/128504/2 "2018-05-16T10:05:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
