# Grok multiline parse failures

**URL:** <https://discuss.elastic.co/t/grok-multiline-parse-failures/104607>\
**Category:** Logstash\
**Created:** [October 19, 2017, 6:47pm UTC](https://discuss.elastic.co/t/grok-multiline-parse-failures/104607 "2017-10-19T18:47:42Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jordan160](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jordan160/32/23202_2.png) [@Jordan160](https://discuss.elastic.co/u/Jordan160)\
**Post date:** [October 19, 2017, 6:47pm UTC](https://discuss.elastic.co/t/grok-multiline-parse-failures/104607/1 "2017-10-19T18:47:42Z")

</div>

Hello,

I am fairly new to ELK stack and currently am having issues with GROK filter.

My pattern matches when using [http://grokconstructor.appspot.com](http://grokconstructor.appspot.com), but it still seems to be breaking on a particular log pattern that has multiple lines/spaces.

Example log:

2017-10-19 13:35:03,732 ERROR [org.jboss.msc.service.fail] (MSC service thread 1-7) MSC000001: Failed to start service jboss.undertow.listener.default: org.jboss.msc.service.StartException in service jboss.undertow.listener.default: Could not start http listener  
at org.wildfly.extension.undertow.ListenerService.start(ListenerService.java:150)  
at org.jboss.msc.service.ServiceControllerImpl$StartTask.startService(ServiceControllerImpl.java:1948)  
at org.jboss.msc.service.ServiceControllerImpl$StartTask.run(ServiceControllerImpl.java:1881)  
at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1142)  
at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:617)  
at java.lang.Thread.run(Thread.java:745)

Pattern I'm using:

match =\> [message =\> "(?m)%{TIMESTAMP\_ISO8601:timestamp}\s+%{LOGLEVEL:loglevel}%{SPACE}[%{DATA:class}]\s(%{DATA:thread})\s(?(.|\r|\n)\*)" ]

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/7/b7139d3aa1b76ea1a99e8ba6be68b5d7d9825dac.png)

Any suggestions is greatly appreciated.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 19, 2017, 7:17pm UTC](https://discuss.elastic.co/t/grok-multiline-parse-failures/104607/2 "2017-10-19T19:17:10Z")

</div>

Why do you need all the `(?(.|\r|\n)*)` stuff at the end? Don't you want to catch everything after the thread name in one field?

Don't use DATA in multiple places. You don't need it. Use `(?<class>[^\]]+)` and `(?<thread>[^)]+)` instead. (Side node: I suspect "class" is the wrong fieldname. I suspect it's actually the logger name, although the logger name usually happens to be the same as the class name.)

---

<div class="post-metadata">

**Author:** ![Jordan160](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jordan160/32/23202_2.png) [@Jordan160](https://discuss.elastic.co/u/Jordan160)\
**Post date:** [October 19, 2017, 7:36pm UTC](https://discuss.elastic.co/t/grok-multiline-parse-failures/104607/3 "2017-10-19T19:36:08Z")

</div>

> [@Jordan160](#):
>
> (?(.|\r|\n)\*)" ]

Thanks for the reply.

I've replaced class/thread with your suggestions. My goal is to capture everything after thread into a field "logmessage".

I've tried: (?(.|\r|\n)\*) and %{GREEDYDATA:logmessage} but both appear to not parse the next lines and give me the grokparseerror:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/5/156ee3849b4b169898247ee44dabd8e345565bdf.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/5/356a10978be2b22c064cd92cdceef8d044be56a2.png)

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 19, 2017, 8:01pm UTC](https://discuss.elastic.co/t/grok-multiline-parse-failures/104607/4 "2017-10-19T20:01:49Z")

</div>

I'm pretty sure GREEDYDATA matches newlines. What if you leave out that part at the end, does that make the grok expression work?

---

<div class="post-metadata">

**Author:** ![Jordan160](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jordan160/32/23202_2.png) [@Jordan160](https://discuss.elastic.co/u/Jordan160)\
**Post date:** [October 19, 2017, 8:12pm UTC](https://discuss.elastic.co/t/grok-multiline-parse-failures/104607/5 "2017-10-19T20:12:54Z")

</div>

It does not work because it tries to evaluate the next line as a new line still:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/2/f2fa8605a65e6758d5142cf48a5c2f2115dcff79.png)

I've tried switching the pattern between pattern =\> "^[[:digit:]]{4}-[[:digit:]]{2}-[[:digit:]]{2}" and pattern =\> "^(?!201)" but it is still not parsing these lines correctly.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 20, 2017, 4:41am UTC](https://discuss.elastic.co/t/grok-multiline-parse-failures/104607/6 "2017-10-20T04:41:33Z")

</div>

Oh, so it's really a multiline codec problem. That wasn't clear at all. Don't use the multiline codec with the Beats input. Do multiline processing on the Filebeat side. [Its documentation](https://www.elastic.co/guide/en/beats/filebeat/current/multiline-examples.html) contains an example of almost exactly your kind of log.

---

<div class="post-metadata">

**Author:** ![Jordan160](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jordan160/32/23202_2.png) [@Jordan160](https://discuss.elastic.co/u/Jordan160)\
**Post date:** [October 20, 2017, 3:58pm UTC](https://discuss.elastic.co/t/grok-multiline-parse-failures/104607/7 "2017-10-20T15:58:39Z")

</div>

That did the trick, thanks a bunch for your help!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 17, 2017, 3:58pm UTC](https://discuss.elastic.co/t/grok-multiline-parse-failures/104607/8 "2017-11-17T15:58:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
