# Grok parsing for multiline logs (winlogbeat)

**URL:** <https://discuss.elastic.co/t/grok-parsing-for-multiline-logs-winlogbeat/67302>\
**Category:** Logstash\
**Created:** [November 28, 2016, 5:16am UTC](https://discuss.elastic.co/t/grok-parsing-for-multiline-logs-winlogbeat/67302 "2016-11-28T05:16:23Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Houss](https://avatars.discourse-cdn.com/v4/letter/h/a88e4f/32.png) [@Houss](https://discuss.elastic.co/u/Houss)\
**Post date:** [November 28, 2016, 5:16am UTC](https://discuss.elastic.co/t/grok-parsing-for-multiline-logs-winlogbeat/67302/1 "2016-11-28T05:16:23Z")

</div>

Hello,

I'm having problem making the grok parsing work for multiline log. I've tried \n or \r or both and can't seem to make it work. Here's an example :

Niveau d’emprunt d’identité : Emprunt d’identité

```
Nouvelle ouverture de session :
	ID de sécurité : S-1-5-21-1519999410-1935793592-2975913076-18531
	Nom du compte : PC154196$
	Domaine du compte : CG974
	ID d’ouverture de session : 0x4FE8C2E1
	GUID d’ouverture de session : {20A5E327-04E7-6178-3818-E9A074BAC6F3}

Informations sur le processus :
	ID du processus : 0x0
	Nom du processus : -

```

Let's say I want to catch the "Nom du compte :", here is what I tried :

- `Nouvelle ouverture de session\s:.+Nom du compte\s:\s+%{NOTSPACE:user_account}`
- `Nouvelle ouverture de session\s:\n.+\n.+Nom du compte\s:\s+%{NOTSPACE:user_account}`
- `Nouvelle ouverture de session\s:(\n|\r|\n\r).+(\n|\r|\n\r).+Nom du compte\s:\s+%{NOTSPACE:user_account}`  
Please note that I can't just put `Nom du compte\s:\s+%{NOTSPACE:user_account}` as there are two lines like this in the log.

Any insights on this ?  
Thanks !

---

<div class="post-metadata">

**Author:** ![Houss](https://avatars.discourse-cdn.com/v4/letter/h/a88e4f/32.png) [@Houss](https://discuss.elastic.co/u/Houss)\
**Post date:** [November 28, 2016, 5:37am UTC](https://discuss.elastic.co/t/grok-parsing-for-multiline-logs-winlogbeat/67302/2 "2016-11-28T05:37:06Z")

</div>

Also, using the multiline codec splits the log in several parts and I would like to avoid that.

---

<div class="post-metadata">

**Author:** ![Houss](https://avatars.discourse-cdn.com/v4/letter/h/a88e4f/32.png) [@Houss](https://discuss.elastic.co/u/Houss)\
**Post date:** [November 28, 2016, 6:31am UTC](https://discuss.elastic.co/t/grok-parsing-for-multiline-logs-winlogbeat/67302/3 "2016-11-28T06:31:28Z")

</div>

I upgraded to winlogbeats 5.0 and it seeems that I won't need to parse the events myself since it is already creating the fields I'm interested in 😄

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 26, 2016, 6:31am UTC](https://discuss.elastic.co/t/grok-parsing-for-multiline-logs-winlogbeat/67302/4 "2016-12-26T06:31:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
