# Grok Filter Logstash Multiple Lines

**URL:** <https://discuss.elastic.co/t/grok-filter-logstash-multiple-lines/94237>\
**Category:** Logstash\
**Created:** [July 23, 2017, 10:40am UTC](https://discuss.elastic.co/t/grok-filter-logstash-multiple-lines/94237 "2017-07-23T10:40:11Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![lavolpem](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lavolpem/32/20344_2.png) [@lavolpem](https://discuss.elastic.co/u/lavolpem)\
**Post date:** [July 23, 2017, 10:40am UTC](https://discuss.elastic.co/t/grok-filter-logstash-multiple-lines/94237/1 "2017-07-23T10:40:11Z")

</div>

# I have some problem about the log's format that I had to parse. My logs have a format like this: `================================================================== Report : WARNING Date : Thu Jun 18 16:52:54 2017 Description : Did not install signal handlers to cleanup resources. Node : swim-host Process : java \<14517\> Thread : main thread 40ea6940 Internals : V6.3.130716OSS

Report : INFO  
Date : Thu Jun 18 16:52:59 2017  
........ .........`  
and following like that. So in my case the separator between the single instances is the sequence of 88 "=". But grok filter considers by default as separator the end of line. So when I start logstash I have a grokparsefailure because it applies the grok filter, that I wrote for the entire instance, to just one line. For example if I try to parse a .log file whit just one instance of collected data and I start logstash I have 8 grokparsefailure, one for each line. I tried with the codec multiline or the gsub mutate filter but I couldn't solve the problem. How can I solve the issue?

---

<div class="post-metadata">

**Author:** ![marcelo](https://avatars.discourse-cdn.com/v4/letter/m/f17d59/32.png) [@marcelo](https://discuss.elastic.co/u/marcelo)\
**Post date:** [July 23, 2017, 9:49pm UTC](https://discuss.elastic.co/t/grok-filter-logstash-multiple-lines/94237/2 "2017-07-23T21:49:46Z")

</div>

Try this grok filter

```
^================================================================== 
Report : %{NOTSPACE:Report}
Date : %{DAY:day} %{MONTH:month} %{MONTHDAY:day} %{TIME:hour} %{YEAR:year}
Description : %{DATA:Description}.
Node : %{NOTSPACE:node}
Process : %{DATA:Process}
Thread : %{DATA:Thread}
Internals : %{NOTSPACE:Internals}

```

works on [https://grokdebug.herokuapp.com/](https://grokdebug.herokuapp.com/) with:

INPUT:

```
================================================================== 
Report : WARNING
Date : Thu Jun 18 16:52:54 2017
Description : Did not install signal handlers to cleanup resources.
Node : swim-host
Process : java <14517>
Thread : main thread 40ea6940
Internals : V6.3.130716OSS

```

PATTERN:

```
^================================================================== 
Report : %{NOTSPACE:Report}
Date : %{DAY:day} %{MONTH:month} %{MONTHDAY:day} %{TIME:hour} %{YEAR:year}
Description : %{DATA:Description}.
Node : %{NOTSPACE:node}
Process : %{DATA:Process}
Thread : %{DATA:Thread}
Internals : %{NOTSPACE:Internals}

```

RESULT:

```
    {
  "Report": [
    [
      "WARNING"
    ]
  ],
  "day": [
    [
      "Thu"
    ],
    [
      "18"
    ]
  ],
  "month": [
    [
      "Jun"
    ]
  ],
  "hour": [
    [
      "16:52:54"
    ]
  ],
  "HOUR": [
    [
      "16"
    ]
  ],
  "MINUTE": [
    [
      "52"
    ]
  ],
  "SECOND": [
    [
      "54"
    ]
  ],
  "year": [
    [
      "2017"
    ]
  ],
  "Description": [
    [
      "Did not install signal handlers to cleanup resources"
    ]
  ],
  "node": [
    [
      "swim-host"
    ]
  ],
  "Process": [
    [
      "java <14517>"
    ]
  ],
  "Thread": [
    [
      "main thread 40ea6940"
    ]
  ],
  "Internals": [
    [
      "V6.3.130716OSS"
    ]
  ]
}
```

---

<div class="post-metadata">

**Author:** ![CDR](https://avatars.discourse-cdn.com/v4/letter/c/d9b06d/32.png) [@CDR](https://discuss.elastic.co/u/CDR)\
**Post date:** [July 24, 2017, 7:11pm UTC](https://discuss.elastic.co/t/grok-filter-logstash-multiple-lines/94237/3 "2017-07-24T19:11:02Z")

</div>

Can you post your configuration file? Also, are you wanting to group the message in between the = signs as one event or each line seperate?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 21, 2017, 7:11pm UTC](https://discuss.elastic.co/t/grok-filter-logstash-multiple-lines/94237/4 "2017-08-21T19:11:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
