# Grok to multiline ingestion does not handle rows

**URL:** <https://discuss.elastic.co/t/grok-to-multiline-ingestion-does-not-handle-rows/292412>\
**Category:** Logstash\
**Created:** [December 19, 2021, 7:24pm UTC](https://discuss.elastic.co/t/grok-to-multiline-ingestion-does-not-handle-rows/292412 "2021-12-19T19:24:37Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![tjswe](https://avatars.discourse-cdn.com/v4/letter/t/8e7dd6/32.png) [@tjswe](https://discuss.elastic.co/u/tjswe)\
**Post date:** [December 19, 2021, 7:24pm UTC](https://discuss.elastic.co/t/grok-to-multiline-ingestion-does-not-handle-rows/292412/1 "2021-12-19T19:24:37Z")

</div>

Hi!

Im ingesting .txt-files containing navtex-messages (see example below). Each message comes in a separate .txt-file appearing continuously over 24h landning in a sub-directory with the current date.

```auto
input {
    file {
        path => "/navtex/*/*.txt"
        start_position => "beginning"
        mode => "read"
        codec => multiline {
        pattern => "^Spalzani"
        negate => true
        what => "previous"
        auto_flush_interval => 1
        }

    }
}

```

Ingestion works ok. Each message gets indexed looking good.

But i can not get a grok working correctly. I need to get grok the row containing "NAV WARNING" and it almost works.

`match => { "message" => "^%{DATA:nav_warn_location} NAV WARN %{NUMBER:nav_warn_id}(/%{NUMBER:year})?" }`

The above gives **"nav\_warn\_id : 552"** and **"year : 21"** , but the ^%{DATA:nav\_warn\_location} Takes the whole beginning of the message not considering the start of the row.

Navtex Bulletin Received (UTC):  
2021-12-19 17:30:38

ZCZC JA67  
111050 UTC DEC  
GERMAN

Expected output would be **"nav\_warn\_location : GERMAN"**

It works when i try it in the dev-tools, but it has probably something to do with the multiline stuff.

Beginner in this so probably something im missing... Any clues?

Navtex Bulletin Received (UTC):  
2021-12-19 17:30:38

ZCZC JA67  
111050 UTC DEC  
GERMAN NAV WARN 552/21  
WESTERN BALTIC.DECLARED AREA TODENDORF/PUTLOS.  
SEVERAL CAUTION AREA BUOYS TEMPORARILY REMOVED.  
NNNN

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [December 19, 2021, 8:07pm UTC](https://discuss.elastic.co/t/grok-to-multiline-ingestion-does-not-handle-rows/292412/2 "2021-12-19T20:07:19Z")

</div>

Try

```
match => { "message" => "^(?<nav_warn_location>[^\n]+) NAV WARN %{NUMBER:nav_warn_id}(/%{NUMBER:year})?" }
```

---

<div class="post-metadata">

**Author:** ![tjswe](https://avatars.discourse-cdn.com/v4/letter/t/8e7dd6/32.png) [@tjswe](https://discuss.elastic.co/u/tjswe)\
**Post date:** [December 19, 2021, 8:17pm UTC](https://discuss.elastic.co/t/grok-to-multiline-ingestion-does-not-handle-rows/292412/3 "2021-12-19T20:17:56Z")

</div>

Second post here, and once again Badger clocking a reply under an hour. Many thanks! Works like a charm!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 16, 2022, 8:18pm UTC](https://discuss.elastic.co/t/grok-to-multiline-ingestion-does-not-handle-rows/292412/4 "2022-01-16T20:18:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
