# Grok pattern when last field can be multiline

**URL:** <https://discuss.elastic.co/t/grok-pattern-when-last-field-can-be-multiline/26906>\
**Category:** Logstash\
**Created:** [August 5, 2015, 4:25pm UTC](https://discuss.elastic.co/t/grok-pattern-when-last-field-can-be-multiline/26906 "2015-08-05T16:25:37Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![FrankC](https://avatars.discourse-cdn.com/v4/letter/f/ed655f/32.png) [@FrankC](https://discuss.elastic.co/u/FrankC)\
**Post date:** [August 5, 2015, 4:25pm UTC](https://discuss.elastic.co/t/grok-pattern-when-last-field-can-be-multiline/26906/1 "2015-08-05T16:25:37Z")

</div>

I am trying to come up with a solution for a log file that is pipe delimited with the last field could be a multiline.

Example:  
a|b|this is  
multiline  
c|d|no mutliline

Any pointers would be appreciated.

Also, since the file is fixed format (i.e. csv) is there any advantage of using grok pattern filter vs. a csv filter?

Thanks,  
Frank.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 5, 2015, 4:43pm UTC](https://discuss.elastic.co/t/grok-pattern-when-last-field-can-be-multiline/26906/2 "2015-08-05T16:43:00Z")

</div>

How do you know that a line is a continuation of the previous line? That is doesn't contain a pipe character?

---

<div class="post-metadata">

**Author:** ![FrankC](https://avatars.discourse-cdn.com/v4/letter/f/ed655f/32.png) [@FrankC](https://discuss.elastic.co/u/FrankC)\
**Post date:** [August 5, 2015, 4:50pm UTC](https://discuss.elastic.co/t/grok-pattern-when-last-field-can-be-multiline/26906/3 "2015-08-05T16:50:30Z")

</div>

Here is what the last field looks like: Hope this helps.  
Uncaught Exception in SilentScope: IESessionImpl:processDPCommandsEx: 0.368 Args=(Operation="306032") Vars=(Method Call Parameter Operation="306032")  
EntityActivityNotifier.cpp:114:GenericContainer::EntityActivityNotifierWithTLSContext::~EntityActivityNotifierWithTLSContext(): TraceLog message 2796  
|63ae678f-b640-74fc-d255-2954640f444e|2015 08 03 16:07:30:094|...... this line is a new event

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 5, 2015, 4:53pm UTC](https://discuss.elastic.co/t/grok-pattern-when-last-field-can-be-multiline/26906/4 "2015-08-05T16:53:03Z")

</div>

So any line that _does not_ begin with a pipe should be joined with the next line, then? That means you need a multiline filter or codec configured like this:

```
multiline {
  pattern => "^\|"
  negate => true
  what => "previous"
}
```

---

<div class="post-metadata">

**Author:** ![FrankC](https://avatars.discourse-cdn.com/v4/letter/f/ed655f/32.png) [@FrankC](https://discuss.elastic.co/u/FrankC)\
**Post date:** [August 5, 2015, 4:59pm UTC](https://discuss.elastic.co/t/grok-pattern-when-last-field-can-be-multiline/26906/5 "2015-08-05T16:59:53Z")

</div>

Thanks Magnus. The pipe delimiter on the second line in my example is actually is there b/c the first field on that line seems to be null. So, the newline does not begin with a pipe.

Here are two lines from the log. The first field is null. The second field is the guid followed by a timestamp, etc.

|f74d0e36-fd45-91fe-7cf3-fb0e2b6a7bdb|2015 08 03 16:07:30:094|Uncaught Exception in SilentScope: IESessionImpl:processDPCommandsEx: 0.368 Args=(Operation="306032") Vars=(Method Call Parameter Operation="306032")  
EntityActivityNotifier.cpp:114:GenericContainer::EntityActivityNotifierWithTLSContext::~EntityActivityNotifierWithTLSContext(): TraceLog message 2796  
|63ae678f-b640-74fc-d255-2954640f444e|2015 08 03 16:07:30:094|GenericContainer\_EntityActivityNotifier:EntityActivityNotifierWithTLSContext\_Destructor  
EntityActivityNotifier.cpp:114:GenericContainer::EntityActivityNotifierWithTLSContext::~EntityActivityNotifierWithTLSContext(): TraceLog message 2797

Adding output from logstash. You can see how it broke up the message in two part. One thing I noticed is the \u001E at the end.

{"message":["|f74d0e36-fd45-91fe-7cf3-fb0e2b6a7bdb|2015 08 03 16:07:30:094|Uncaught Exception in SilentScope: IESessionImpl:processDPCommandsEx: 0.368 Args=(Operation=306032) Vars=(Method Call Parameter Operation=306032)\u001E\r"],"@version":"1","@timestamp":"2015-08-05T17:36:54.967Z","type":"webi","host":"mylaptop","path":"log\_file","Location":null,"Guid":"f74d0e36-fd45-91fe-7cf3-fb0e2b6a7bdb","Time":"2015 08 03 16:07:30:094","Text":"Uncaught Exception in SilentScope: IESessionImpl:processDPCommandsEx: 0.368 Args=(Operation=306032) Vars=(Method Call Parameter Operation=306032)\u001E"}  
{"message":["EntityActivityNotifier.cpp:114:GenericContainer::EntityActivityNotifierWithTLSContext::~EntityActivityNotifierWithTLSContext(): TraceLog message 2796\r"],"@version":"1","@timestamp":"2015-08-05T17:36:54.967Z","type":"webi","host":"mylaptop","path":"log\_file","Location":"EntityActivityNotifier.cpp:114:GenericContainer::EntityActivityNotifierWithTLSContext::~EntityActivityNotifierWithTLSContext(): TraceLog message 2796"}

Update: I have tried the multiline and it does not seem to make one message.

Any other thoughts on this?

---

<div class="post-metadata">

**Author:** ![FrankC](https://avatars.discourse-cdn.com/v4/letter/f/ed655f/32.png) [@FrankC](https://discuss.elastic.co/u/FrankC)\
**Post date:** [August 6, 2015, 4:58pm UTC](https://discuss.elastic.co/t/grok-pattern-when-last-field-can-be-multiline/26906/7 "2015-08-06T16:58:25Z")

</div>

Update: I resolved the multiline issue. Followed what Magnum suggested. I had a typo .Duh!

Thanks again for helping with this.

Regards,  
Frank.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:32am UTC](https://discuss.elastic.co/t/grok-pattern-when-last-field-can-be-multiline/26906/8 "2017-07-06T05:32:43Z")

</div>


