# How to parsing multiline messages with conditionals issues in Logstash?

**URL:** <https://discuss.elastic.co/t/how-to-parsing-multiline-messages-with-conditionals-issues-in-logstash/55257>\
**Category:** Logstash\
**Created:** [July 12, 2016, 2:36am UTC](https://discuss.elastic.co/t/how-to-parsing-multiline-messages-with-conditionals-issues-in-logstash/55257 "2016-07-12T02:36:04Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kennedy\_Kan1](https://avatars.discourse-cdn.com/v4/letter/k/cc9497/32.png) [@Kennedy\_Kan1](https://discuss.elastic.co/u/Kennedy_Kan1)\
**Post date:** [July 12, 2016, 2:36am UTC](https://discuss.elastic.co/t/how-to-parsing-multiline-messages-with-conditionals-issues-in-logstash/55257/1 "2016-07-12T02:36:04Z")

</div>

I have a log file reading through the ftp process and I am using logstash to ingest the data.

A sample record is like that

```
Enter an FTP subcommand.
> PUT REPE533 AMTD_Statusfile.txt
227 Entering Passive Mode (10,133,104,90,7,136).
125 Data connection already open; Transfer starting.
226 Transfer complete.
157320 bytes transferred in 0.005 seconds. Transfer rate 32219.137 KB/sec.
Enter an FTP subcommand.
> QUIT

```

I just want to extract the message `PUT REPE533 AMTD_Statusfile.txt` and `Transfer complete` **How should I grok the message with logstash?** Here is the filter part of my config file.

```
if ([message] =~ /PUT/){
    multiline{
        pattern => "> "
        what => "next"
    }
	grok{
		match => {"message" => ['> %{GREEDYDATA: Command}\r\n%{GREEDYDATA:Message}\r\n%{SPACE}Enter an FTP subcommand.'] }
	}
	if ([Message] =~ /(Transfer Complete)/){    		
		mutate {
			add_field => {"Status" => "Transfer Complete"}
			add_tag => "send_to_es"
		}
	}
	mutate {
		remove_field => "%{Message}"
		add_tag => "send_to_es"
	}
}
```

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 12, 2016, 5:45am UTC](https://discuss.elastic.co/t/how-to-parsing-multiline-messages-with-conditionals-issues-in-logstash/55257/2 "2016-07-12T05:45:32Z")

</div>

Again, I suspect the aggregate filter will help you.

---

<div class="post-metadata">

**Author:** ![Kennedy\_Kan1](https://avatars.discourse-cdn.com/v4/letter/k/cc9497/32.png) [@Kennedy\_Kan1](https://discuss.elastic.co/u/Kennedy_Kan1)\
**Post date:** [July 12, 2016, 6:21am UTC](https://discuss.elastic.co/t/how-to-parsing-multiline-messages-with-conditionals-issues-in-logstash/55257/3 "2016-07-12T06:21:03Z")

</div>

Sorry, I could not understand how aggregate plugin can help me. Currently, I can extract the message separately if I did not use multiline function. However, when I use multiline function and try to group the message together into grok for analysis, it will just ignore the multiline pattern and read back the lines as a single message. How should I combine them as a message?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:48am UTC](https://discuss.elastic.co/t/how-to-parsing-multiline-messages-with-conditionals-issues-in-logstash/55257/4 "2017-07-06T04:48:32Z")

</div>


