# Gelf input with multiline

**URL:** <https://discuss.elastic.co/t/gelf-input-with-multiline/235918>\
**Category:** Logstash\
**Created:** [June 5, 2020, 8:52am UTC](https://discuss.elastic.co/t/gelf-input-with-multiline/235918 "2020-06-05T08:52:52Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![111228](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/111228/32/56505_2.png) [@111228](https://discuss.elastic.co/u/111228)\
**Post date:** [June 5, 2020, 8:52am UTC](https://discuss.elastic.co/t/gelf-input-with-multiline/235918/1 "2020-06-05T08:52:53Z")

</div>

Hello all  
Tell me how to configure correctly PHP errors with Stack trace in multiline.  
I have such messages  
1 message ) `[05-Jun-2020 11:35:39 Europe/Kiev] PHP Fatal error: require(): Failed opening required 'askldjalksnas' (include_path='.:/usr/local/lib/php') in /srv/src/myproject/sites/workfolder/121/error.php on line 3`  
2 message )  
`[05-Jun-2020 11:35:39 Europe/Kiev] PHP Stack trace: `  
3 message )   
`[05-Jun-2020 11:35:39 Europe/Kiev] PHP 1. {main}() /srv/src/myproject/sites/workfolder/121/error.php:0 `

But I want to connect these messages  
my settings:  
Input  
gelf {  
port\_udp =\> 14223  
tags =\> naf1\_php  
use\_udp =\> true  
type =\> naf1\_php  
host =\> "0.0.0.0"  
codec =\> multiline {  
pattern =\> "(.+PHP Stack trace: .+)"  
negate =\> true  
what =\> "previous"  
}  
}

filter  
grok {  
match =\> ["message", "[%{MONTHDAY:day}-%{MONTH:month}-%{YEAR:year} %{TIME:time} %{WORD:zone}/%{WORD:country}] PHP %{DATA:error\_level}: %{GREEDYDATA:error}" ]  
add\_field =\> { "timestamp" =\> "%{day}-%{month}-%{year} %{time} %{zone}/%{country}" }  
add\_tag =\> ["%{level}"]  
remove\_field =\> ["day", "month", "year", "time", "zone", "country"]  
}

But it doesn 't work  
I tried to change pattern on "(.+PHP Stack trace: .+)" But it didn 't help too

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 5, 2020, 2:11pm UTC](https://discuss.elastic.co/t/gelf-input-with-multiline/235918/2 "2020-06-05T14:11:21Z")

</div>

Please do not post pictures of text, they are hard to read and not searchable.

---

<div class="post-metadata">

**Author:** ![111228](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/111228/32/56505_2.png) [@111228](https://discuss.elastic.co/u/111228)\
**Post date:** [June 5, 2020, 2:31pm UTC](https://discuss.elastic.co/t/gelf-input-with-multiline/235918/3 "2020-06-05T14:31:17Z")

</div>

Sorry I remade

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 5, 2020, 3:25pm UTC](https://discuss.elastic.co/t/gelf-input-with-multiline/235918/4 "2020-06-05T15:25:27Z")

</div>

> [@111228](#):
>
> pattern =\> "(.+PHP Stack trace: .+)"

You do not need the (.+ or the .+), and there is no space after the colon in your sample data, so this will never match.

There is not really enough sample data to make it clear what you want to do. If you want to combine those three lines then

```
 pattern => 'PHP Stack trace:|PHP Fatal error' negate => false what => "next"

```

might be good for you. However, if you want to handle a multi-line stack trace you pretty much have to use

```
 pattern => 'PHP Stack trace:' negate => true what => "previous"

```

but that will capture the _following_ 'PHP Fatal error', not the previous one. I suspect a multiline codec cannot do what you want to do.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 3, 2020, 3:25pm UTC](https://discuss.elastic.co/t/gelf-input-with-multiline/235918/5 "2020-07-03T15:25:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
