# Guidance for parsing log file

**URL:** <https://discuss.elastic.co/t/guidance-for-parsing-log-file/165604>\
**Category:** Logstash\
**Created:** [January 24, 2019, 12:37pm UTC](https://discuss.elastic.co/t/guidance-for-parsing-log-file/165604 "2019-01-24T12:37:45Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Hamed\_khosravi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hamed_khosravi/32/39411_2.png) [@Hamed\_khosravi](https://discuss.elastic.co/u/Hamed_khosravi)\
**Post date:** [January 24, 2019, 12:37pm UTC](https://discuss.elastic.co/t/guidance-for-parsing-log-file/165604/1 "2019-01-24T12:37:45Z")

</div>

hi dears  
I trying to pars some log files for WebSphere MQ and I'm not familiar with this logs, some lines of those logs different with others lines. for example :  
""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""  
2018-10-19 13:52:16,188 DEBUG -org.springframework.jms.core.JmsTemplate - Sending created message:  
JMS Message class: jms\_bytes  
JMSType: null  
JMSDeliveryMode: 2  
JMSExpiration: 0  
JMSPriority: 4  
JMSMessageID: null  
JMSTimestamp: 0  
JMSCorrelationID:null  
JMSDestination: null  
JMSReplyTo: null  
JMSRedelivered: false  
Integer encoding: 1, Floating point encoding 256  
342334eseffsdgyfuk8a6ad576c42ffc30477955eb8f43840596286561521b994e9c448c  
f6424b8c4efluglusad3e16752fde484225f81a43c4499a0c9556c12b3417b67a6b57848b11f65ab1  
ec00480d1f0fbea414f7881ac190bdf5b705e49471d7da626e2a922f81b0edc10aa179a75a2e87bb6c0be8955591c4d9700c  
""""""""""""""""""""""""""""""""""""""""""""""""

and the other line may look like this :

"""""""""  
2018-10-19 13:52:16,226 DEBUG -com.ada.msas.switchingImpl.SwitchingImpl - 1470490# SwitchingImpl.switching msg :  
SERVICE\_CODE:00 ACCOUNT\_NUMEBR:00000000000000 REQUEST\_DATE\_TIME:0 AMOUNT:000005000000 ACTION\_CODE:0000 RESPONSE\_DATE\_TIME:0000000000000 ORIGIN\_ACTION\_CODE:00 SOURCE\_TYPE:2 LATITUDE:0.0 LONGITUDE:0.0 PARENT\_IMF:0 OPERATOR\_TYPE:0 STAN:000000000 DIRECTION:RES INTERNAL\_ID:00000000 MEDIA\_TYPE:0 TOPUP\_TYPE:0 TOPUP\_PROFILE:0

"""""""""""""""""""""""""""""""""""""""""""""""

how can I read those lines with logstash? the both of these line logged in one file.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 24, 2019, 1:34pm UTC](https://discuss.elastic.co/t/guidance-for-parsing-log-file/165604/2 "2019-01-24T13:34:09Z")

</div>

Use a file input with a multiline codec

```
codec => multiline {
    pattern => "^%{TIMESTAMP_ISO8601} "
    negate => true
    what => "previous"
}
```

---

<div class="post-metadata">

**Author:** ![Hamed\_khosravi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hamed_khosravi/32/39411_2.png) [@Hamed\_khosravi](https://discuss.elastic.co/u/Hamed_khosravi)\
**Post date:** [January 26, 2019, 8:19am UTC](https://discuss.elastic.co/t/guidance-for-parsing-log-file/165604/3 "2019-01-26T08:19:44Z")

</div>

thanks for reply, could you please describe it to me step by step?! i'm not fimiliar with multiline, what plugins should i install?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 23, 2019, 8:19am UTC](https://discuss.elastic.co/t/guidance-for-parsing-log-file/165604/4 "2019-02-23T08:19:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
