# Grok Pattern/Expression for Multiline log from kibana (icingabeat index)

**URL:** https://discuss.elastic.co/t/grok-pattern-expression-for-multiline-log-from-kibana-icingabeat-index/273059
**Category:** Logstash
**Created:** [May 14, 2021, 7:05pm UTC](https://discuss.elastic.co/t/grok-pattern-expression-for-multiline-log-from-kibana-icingabeat-index/273059 "2021-05-14T19:05:36Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![shailesh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shailesh/32/92646_2.png) [@shailesh](https://discuss.elastic.co/u/shailesh)
#### Post date: [May 14, 2021, 7:05pm UTC](https://discuss.elastic.co/t/grok-pattern-expression-for-multiline-log-from-kibana-icingabeat-index/273059/1 "2021-05-14T19:05:36Z")

</div>

Hello Team - I am trying to process some data from icinagbeat index from Kibana- so that i can visualize the output from icinagbeat - for that reason i am writing the Grok pattern - but the problem is when i write the pattern for one by one single line it all works fine - but the issue is i am unable to parse all the lines together - posting the output from Kibana for which i am trying to get the Grok pattern for  
Totalopenfiledescriptors - is XXXX  
Thresholdvalue for openfiledescriptors - is XXXX  
processesrunning-html5client - XX  
Total Sessions on a stitcher - is XX

- The above 4 lines are the output lines from icingabeat index for which i am trying to write the pattern for -  
And the Grok Pattern i came up with is  
Totalopenfiledescriptors - is %{NUMBER:Total\_open\_filedescriptors}, Thresholdvalue for openfiledescriptors - is %{NUMBER:Thresholdvalue\_for\_openfiledescriptors}, processesrunning-html5client - %{NUMBER:processesrunning-html5client}, Total Sessions on a stitcher - is %{NUMBER:Total\_Sessions\_on\_stitcher}

i am trying to process all the lines together - please let us know if there is a way ? or if i am not going in the correct direction -  
Thanks in Advance  
@shailesh

---

<div class="post-metadata">

### Author: ![Cad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cad/32/86661_2.png) [@Cad](https://discuss.elastic.co/u/Cad)
#### Post date: [May 16, 2021, 9:05pm UTC](https://discuss.elastic.co/t/grok-pattern-expression-for-multiline-log-from-kibana-icingabeat-index/273059/2 "2021-05-16T21:05:39Z")

</div>

Hi,

You have 4 grok pattern, one for each line, but you seperated them with '`, `' why ?  
Replace each '`, `' by a `[\n]` resolve your error.

Cad.

---

<div class="post-metadata">

### Author: ![shailesh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shailesh/32/92646_2.png) [@shailesh](https://discuss.elastic.co/u/shailesh)
#### Post date: [May 18, 2021, 2:38pm UTC](https://discuss.elastic.co/t/grok-pattern-expression-for-multiline-log-from-kibana-icingabeat-index/273059/3 "2021-05-18T14:38:36Z")

</div>

Hello Cad - Thank you so much for the response - I am attaching a Screenshot - am i doing something wrong here ?

 ![Results](https://us1.discourse-cdn.com/elastic/original/3X/0/9/09c446e7235d6d7fe46bfee14cc3bc186af79654.png)

---

<div class="post-metadata">

### Author: ![Cad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cad/32/86661_2.png) [@Cad](https://discuss.elastic.co/u/Cad)
#### Post date: [May 18, 2021, 9:53pm UTC](https://discuss.elastic.co/t/grok-pattern-expression-for-multiline-log-from-kibana-icingabeat-index/273059/4 "2021-05-18T21:53:20Z")

</div>

Hi,

The pattern is not working because of the `",` at the end.  
I must specify that the pattern your trying to use work if all the data come at the same time.  
If the values come line by line, you have to split all the pattern like this :

```auto
#One pattern per line
grok {
  match => { "message" => "Totalopenfiledescriptors - is %{NUMBER:Total_open_filedescriptors}",
                          "Thresholdvalue for openfiledescriptors - is %{NUMBER:Thresholdvalue_for_openfiledescriptors}",
                          "processesrunning-html5client - %{NUMBER:processesrunning-html5client}",
                          "Total Sessions on a stitcher - is %{NUMBER:Total_Sessions_on_stitcher}",

           }
}

```

With this configuration, patterns are sequentialy tested until one fit the data in input (so one line of your complete data). Once one pattern is correct, the pipeline leave the grok filter without testing the next patterns.

More about grok [here](https://www.elastic.co/fr/blog/do-you-grok-grok).

Cad.

---

<div class="post-metadata">

### Author: ![shailesh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shailesh/32/92646_2.png) [@shailesh](https://discuss.elastic.co/u/shailesh)
#### Post date: [June 4, 2021, 10:30pm UTC](https://discuss.elastic.co/t/grok-pattern-expression-for-multiline-log-from-kibana-icingabeat-index/273059/5 "2021-06-04T22:30:00Z")

</div>

Thanks Chad for the Response - I did fix it my converting the log message to a single line log message - Thank you for the help 🙂

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 2, 2021, 10:30pm UTC](https://discuss.elastic.co/t/grok-pattern-expression-for-multiline-log-from-kibana-icingabeat-index/273059/6 "2021-07-02T22:30:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
