# Grok multiline coded help

**URL:** <https://discuss.elastic.co/t/grok-multiline-coded-help/131472>\
**Category:** Logstash\
**Created:** [May 11, 2018, 12:05pm UTC](https://discuss.elastic.co/t/grok-multiline-coded-help/131472 "2018-05-11T12:05:49Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![linto](https://avatars.discourse-cdn.com/v4/letter/l/f4b2a3/32.png) [@linto](https://discuss.elastic.co/u/linto)\
**Post date:** [May 11, 2018, 12:05pm UTC](https://discuss.elastic.co/t/grok-multiline-coded-help/131472/1 "2018-05-11T12:05:49Z")

</div>

Hi there,

Could you please help me to create a logstash grok pattern using multiline codec for parsing cobbler logs?

At times, the logs span over multiple lines

Sample log:

```
Mon May 7 05:53:49 2018 - DEBUG | get_items; ['system']
Mon May 7 05:53:49 2018 - DEBUG | done with get_items; ['system']
Mon May 7 05:53:49 2018 - WARNING | warning: kernel option length exceeds 255
Mon May 7 05:53:49 2018 - WARNING | warning: kernel option length exceeds 255
Mon May 7 05:53:49 2018 - WARNING | warning: kernel option length exceeds 255
Mon May 7 05:53:49 2018 - WARNING | warning: kernel option length exceeds 255
Mon May 7 05:53:50 2018 - INFO | generating: /var/lib/tftpboot/pxelinux.cfg/test
Mon May 7 05:53:50 2018 - INFO | generating: /var/lib/tftpboot/grub/TEST
Mon May 7 05:53:50 2018 - INFO | Writing template files for test
Mon May 7 05:53:50 2018 - INFO | REMOTE find_items_paged(system); criteria({}); sort(name); user(?)
Mon May 7 05:53:50 2018 - INFO | find_items; ['system']
Mon May 7 05:53:50 2018 - INFO | REMOTE version; user(testuser)
Mon May 7 05:53:54 2018 - INFO | REMOTE generate_kickstart; user(?)
Mon May 7 05:53:54 2018 - INFO | generate_kickstart
Mon May 7 05:53:54 2018 - ERROR | 
# ***ERROR***
#
# There is a templating error preventing this file from rendering correctly. 
#
# This is most likely not due to a bug in Cobbler and is something you can fix.
#
# Look at the message below to see what things are causing problems.  
#
# (1) Does the template file reference a $variable that is not defined?
# (2) is there a formatting error in a Cheetah directive?
# (3) Should dollar signs ($) be escaped that are not being escaped?
#
# Try fixing the problem and then investigate to see if this message goes
# away or changes.
#
# 
# 'bonding'
# File "/usr/lib/python2.7/site-packages/cobbler/templar.py", line 208, in render_cheetah
# data_out = t.respond()

```

I have tried using below snippet in my logstash conf file:

```
filter {
  if [path] =~ "cobbler.log" {
    grok {
        match => { "message" => "%{DATA:logDatetimeText} - %{WORD:logLevel} \| %{GREEDYDATA:logMessage}" }
    }
    date {
        match => ["logDatetimeText", "EEE MMM d HH:mm:ss YYYY", "EEE MMM dd HH:mm:ss YYYY"]
    }

```

}

This gives me a \_grokparsefailure when it encounters logs spanning multiple lines. So I'm looking at using s multilines code that negates all logs not matching the above specific date pattern. Can someone help me with this please?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 11, 2018, 2:38pm UTC](https://discuss.elastic.co/t/grok-multiline-coded-help/131472/2 "2018-05-11T14:38:28Z")

</div>

I would suggest

```
input { stdin { codec => multiline { pattern => "^(Mon|Tue|Wed|Thu|Fri|Sat|Sun)" negate => true what => "previous" auto_flush_interval => 3 } } }
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 8, 2018, 2:48pm UTC](https://discuss.elastic.co/t/grok-multiline-coded-help/131472/3 "2018-06-08T14:48:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
