# GREEDYDATA and newlines

**URL:** <https://discuss.elastic.co/t/greedydata-and-newlines/45268>\
**Category:** Logstash\
**Created:** [March 23, 2016, 6:00pm UTC](https://discuss.elastic.co/t/greedydata-and-newlines/45268 "2016-03-23T18:00:03Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![CraigFoote](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/craigfoote/32/4571_2.png) [@CraigFoote](https://discuss.elastic.co/u/CraigFoote)\
**Post date:** [March 23, 2016, 6:00pm UTC](https://discuss.elastic.co/t/greedydata-and-newlines/45268/1 "2016-03-23T18:00:03Z")

</div>

I have a log file from a java program coming from filebeat. Some of the events have stacktraces and so are multiline. I'm using the multiline option in filebeat and a grok filter in logstash to parse the event. Everything works well when I end the pattern in %{GREEDYDATA:logmessage} however I'd like to split the "logmessage" at the first newline character and keep the remainder as "stacktrace". What's confusing me is that the "logmessage" field already contains the full stacktrace including "\n" characters! This post, [http://stackoverflow.com/questions/26474873/how-do-i-match-a-newline-in-grok-logstash](http://stackoverflow.com/questions/26474873/how-do-i-match-a-newline-in-grok-logstash), states "`All GREEDYDATA is is .*, but . doesn't match newline`". How does my logmessage field contain newline characters?

I'd like to do something like this:

`SNIP%{GREEDYDATA:logmessage}\n%{GREEDYDATA:stacktrace}`

---

<div class="post-metadata">

**Author:** ![CraigFoote](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/craigfoote/32/4571_2.png) [@CraigFoote](https://discuss.elastic.co/u/CraigFoote)\
**Post date:** [March 23, 2016, 6:46pm UTC](https://discuss.elastic.co/t/greedydata-and-newlines/45268/2 "2016-03-23T18:46:17Z")

</div>

Further, how did my log file with multiple lines end up being a single line with literal \n characters? Is that the work of the multiline option in filebeat?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 23, 2016, 6:51pm UTC](https://discuss.elastic.co/t/greedydata-and-newlines/45268/3 "2016-03-23T18:51:00Z")

</div>

> Further, how did my log file with multiple lines end up being a single line with literal \n characters? Is that the work of the multiline option in filebeat?

Yes, that's why you'd use the multiline option.

---

<div class="post-metadata">

**Author:** ![CraigFoote](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/craigfoote/32/4571_2.png) [@CraigFoote](https://discuss.elastic.co/u/CraigFoote)\
**Post date:** [March 23, 2016, 6:59pm UTC](https://discuss.elastic.co/t/greedydata-and-newlines/45268/4 "2016-03-23T18:59:59Z")

</div>

Ok, thanks Magnus. How then do I split into two fields something like this:

logstash \nrules!

That is, how do I split on the \n?

---

<div class="post-metadata">

**Author:** ![CraigFoote](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/craigfoote/32/4571_2.png) [@CraigFoote](https://discuss.elastic.co/u/CraigFoote)\
**Post date:** [March 23, 2016, 7:18pm UTC](https://discuss.elastic.co/t/greedydata-and-newlines/45268/5 "2016-03-23T19:18:25Z")

</div>

On a related topic, I'm doing this because sometimes "logmessage" includes a huge stacktrace and for whatever reason, it displays blank in kibana. I guess there's a maxlength for a field or something? My thought was to split the logmessage from the stacktrace.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 23, 2016, 8:55pm UTC](https://discuss.elastic.co/t/greedydata-and-newlines/45268/6 "2016-03-23T20:55:23Z")

</div>

> That is, how do I split on the \n?

The mutate filter's split option can certainly split a string, but then you'll split on _all_ newline characters and you just want to split on the first one. It could be that the best way is to write a small Ruby snippet in a ruby filter.

---

<div class="post-metadata">

**Author:** ![CraigFoote](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/craigfoote/32/4571_2.png) [@CraigFoote](https://discuss.elastic.co/u/CraigFoote)\
**Post date:** [March 24, 2016, 12:50pm UTC](https://discuss.elastic.co/t/greedydata-and-newlines/45268/7 "2016-03-24T12:50:40Z")

</div>

Thanks @magnusbaeck. Any thoughts on why large stacktraces appear blank in Kibana? Is there a maximum field size?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:05am UTC](https://discuss.elastic.co/t/greedydata-and-newlines/45268/8 "2017-07-06T05:05:33Z")

</div>


