# How to combine multilines to a single entry in kibana for a log

**URL:** <https://discuss.elastic.co/t/how-to-combine-multilines-to-a-single-entry-in-kibana-for-a-log/265165>\
**Category:** Kibana\
**Created:** [February 23, 2021, 6:45am UTC](https://discuss.elastic.co/t/how-to-combine-multilines-to-a-single-entry-in-kibana-for-a-log/265165 "2021-02-23T06:45:53Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![nikhilesh](https://avatars.discourse-cdn.com/v4/letter/n/46a35a/32.png) [@nikhilesh](https://discuss.elastic.co/u/nikhilesh)\
**Post date:** [February 23, 2021, 6:45am UTC](https://discuss.elastic.co/t/how-to-combine-multilines-to-a-single-entry-in-kibana-for-a-log/265165/1 "2021-02-23T06:45:53Z")

</div>

Hi Team,

Below is the log file , I need to achieve the below scenario's please help me on this.

Scenario 1:

Right now, I was getting the logs in the Kibana dashboard as below. I want all the multiline in the logs should get in to the Kibana as a single entry in the message field (instead of multiple entries for multi lines). can I get the multiline pattern syntax to achieve the same (or) is there any alternative solution for that

FYI.. I am using logstash with multiple hostnames.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/0/308b21bc712a21462ef891b14c4990288a736a0a.png)

Scenario 2:  
How the get all the multiline of the log in to a single entry (how to get in to multiple columns (column 1, column2 ,.....)

Example as below . (instead log.file.path as a column, I want another line to get as side by side)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/2/126ffb1136d16e589bb76b9680738a4b7277fcfa.png)

Log file:

dn: cn=dc=micall,dc=com,cn=domains,cn=Multimaster Synchronization,cn=Synchronization Providers,cn=config  
objectClass: top  
objectClass: ds-cfg-replication-domain  
cn: dc=micall,dc=com  
ds-cfg-base-dn: dc=micall,dc=com  
ds-pwp-password-expiration-time: 20220222062506.252Z  
entryDN: cn=dc=micall,dc=com,cn=domains,cn=Multimaster Synchronization,cn=Synchronization Providers,cn=config  
entryUUID: 3c41d1f5-b7ab-3cc3-ab4b-b8ef29e119e7  
etag: 00020000c39421e9  
hasSubordinates: false  
numSubordinates: 0  
pwdPolicySubentry: cn=Default Password Policy,cn=Password Policies,cn=config  
structuralObjectClass: ds-cfg-replication-domain  
subschemaSubentry: cn=schema

Thanks  
Nick

---

<div class="post-metadata">

**Author:** ![thomasneirynck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thomasneirynck/32/23313_2.png) [@thomasneirynck](https://discuss.elastic.co/u/thomasneirynck)\
**Post date:** [February 23, 2021, 2:46pm UTC](https://discuss.elastic.co/t/how-to-combine-multilines-to-a-single-entry-in-kibana-for-a-log/265165/2 "2021-02-23T14:46:54Z")

</div>

hi @nikhilesh

scenario 1:

This is a logstash question. Here is a tutorial to deal with multi-line logs: [Managing Multiline Events | Logstash Reference [7.11] | Elastic](https://www.elastic.co/guide/en/logstash/current/multiline.html)

You'll end up using the multiline "codec". So you'd end up writing a multiline rule that looks for the `dn:` pattern to indicate the start of your multiline log.

scenario 2:

Once you have done (1), it's concatenated in a single message. You can use a grok pattern to read out the actual values. See here for more [Grok filter plugin | Logstash Reference [master] | Elastic](https://www.elastic.co/guide/en/logstash/master/plugins-filters-grok.html)

---

<div class="post-metadata">

**Author:** ![nikhilesh](https://avatars.discourse-cdn.com/v4/letter/n/46a35a/32.png) [@nikhilesh](https://discuss.elastic.co/u/nikhilesh)\
**Post date:** [February 23, 2021, 4:05pm UTC](https://discuss.elastic.co/t/how-to-combine-multilines-to-a-single-entry-in-kibana-for-a-log/265165/3 "2021-02-23T16:05:43Z")

</div>

Thanks so much.

coming to scenario 1 , my log is not having the dn: pattern as a starting of the multi lines. starting string differ line to line. can you please help me out the exact pattern which can apply?

Thanks  
nick

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 23, 2021, 4:06pm UTC](https://discuss.elastic.co/t/how-to-combine-multilines-to-a-single-entry-in-kibana-for-a-log/265165/4 "2021-03-23T16:06:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
