# Handling multiline that spans log files

**URL:** <https://discuss.elastic.co/t/handling-multiline-that-spans-log-files/363603>\
**Category:** Logs\
**Created:** [July 23, 2024, 5:40am UTC](https://discuss.elastic.co/t/handling-multiline-that-spans-log-files/363603 "2024-07-23T05:40:13Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![kelvins](https://avatars.discourse-cdn.com/v4/letter/k/f19dbf/32.png) [@kelvins](https://discuss.elastic.co/u/kelvins)\
**Post date:** [July 23, 2024, 5:40am UTC](https://discuss.elastic.co/t/handling-multiline-that-spans-log-files/363603/1 "2024-07-23T05:40:13Z")

</div>

So, I have an issue with JDE logs. They rotate whenever the log file gets to ~5 Megabytes. The issue that I am having, is that I am using multiline to gather the log files. What is happening however, is that the multiline may in fact span multiple files as the multiline output may not be in the one file.

Example of a multiline entry, separated by date

```auto
Jul 22, 2024 1:05:01 PM fff fixQuotesAroundSoapAction
INFO: Received HTTP Header:
[BSSVLoginModule : initialize]
log in returned successfully from BSSVWLSLoginModule
[BSSVLoginModule : initialize]
log in returned successfully from BSSVWLSLoginModule

```

However, what I am seeing, is that intermittently, I will get this

file.0001

```auto
Jul 22, 2024 1:05:01 PM fff fixQuotesAroundSoapAction
INFO: Received HTTP Header:
[BSSVLoginModule : initialize]
log in returned successfully from BSSVWLSLoginModule

```

file.0002

```auto
[BSSVLoginModule : initialize]
log in returned successfully from BSSVWLSLoginModule
Jul 22, 2024 1:06:01 PM hhh fixQuotesAroundSoapAction

```

What results is a `_grokparsefailures` due to incorrect log format.

Is there any way to make Elastic Agent continue reading multiline across files?
