# GELF multiline codec doesn't work

**URL:** <https://discuss.elastic.co/t/gelf-multiline-codec-doesnt-work/78929>\
**Category:** Logstash\
**Created:** [March 16, 2017, 8:16pm UTC](https://discuss.elastic.co/t/gelf-multiline-codec-doesnt-work/78929 "2017-03-16T20:16:18Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Josh\_Reichardt](https://avatars.discourse-cdn.com/v4/letter/j/f08c70/32.png) [@Josh\_Reichardt](https://discuss.elastic.co/u/Josh_Reichardt)\
**Post date:** [March 16, 2017, 8:16pm UTC](https://discuss.elastic.co/t/gelf-multiline-codec-doesnt-work/78929/1 "2017-03-16T20:16:18Z")

</div>

I am attempting to set up the multiline input for GELF but it doesn't seem to work and I'm not sure why. Is there a way to debug the multiline input, or does anybody know otherwise why this wouldn't be working?

Here's the configuration. I have tried a number of different patterns but none of them seem to work:

```auto
...
gelf {
        port => 12201
        type => gelf
        codec => multiline {
            pattern => "^\s"
            what => next
        }
    }
...

```

Other relevant details:

- I am sending logs from the Docker daemon from a different machine via the `gelf` log driver
- Logs are showing up in Logstash fine, the multiline functionality is the only part that isn't working
- Docker version is 1.13 for the hosts sending logs, version 1.11 on the ELK side
- Logstash and the rest of the ELK stack is running as a container and is v5.2

Any idea what could be causing the problem or how to fix?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 13, 2017, 8:16pm UTC](https://discuss.elastic.co/t/gelf-multiline-codec-doesnt-work/78929/2 "2017-04-13T20:16:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
