# How to perform concatenation of values from the same field in multiple lines?

**URL:** <https://discuss.elastic.co/t/how-to-perform-concatenation-of-values-from-the-same-field-in-multiple-lines/26729>\
**Category:** Logstash\
**Created:** [August 3, 2015, 3:19pm UTC](https://discuss.elastic.co/t/how-to-perform-concatenation-of-values-from-the-same-field-in-multiple-lines/26729 "2015-08-03T15:19:19Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![djontra](https://avatars.discourse-cdn.com/v4/letter/d/7c8e57/32.png) [@djontra](https://discuss.elastic.co/u/djontra)\
**Post date:** [August 3, 2015, 3:19pm UTC](https://discuss.elastic.co/t/how-to-perform-concatenation-of-values-from-the-same-field-in-multiple-lines/26729/1 "2015-08-03T15:19:19Z")

</div>

Hello,

This is the excerpt from the MS SharePoint log file:

```
Timestamp Process TID Area Category EventID	Level Message Correlation
03/04/2015 15:49:43.01 w3wp.exe (0x1B48) 0x1654	SharePoint Foundation Files ak8dj	High UserAgent not available, file operations may not be optimized...	0577ef9c-e7bf-402c-ea87-f8ab50bf959f
03/04/2015 15:49:43.01*	w3wp.exe (0x1B48) 0x1654	SharePoint Foundation Files ak8dj	High ...) at Microsoft.SharePoint.Library...	0577ef9c-e7bf-402c-ea87-f8ab50bf959f

```

I'm trying to detect multiline message (e.g. by matching asterisk (\*) in the Timestamp field and specifying it as a new field) and then somehow appending value of the log message field from the current line to the previous one.  
Looking at [multiline](https://www.elastic.co/guide/en/logstash/current/plugins-codecs-multiline.html#plugins-codecs-multiline-multiline_tag?q=multiline) codec plugin, much in the same way, except I need to extract and concatenate only one field, not the whole line.

Grok-ing results with:

```
> {"message":"03/04/2015 15:49:43.01 \tw3wp.exe (0x1B48) \t0x1654\tSharePoint Foundation \tFiles \tak8dj\tHigh \tUserAgent not available, file operations may not be optimized...\t0577ef9c-e7bf-402c-ea87-f8ab50bf959f\r","@version":"1","@timestamp":"2015-08-03T14:14:51.994Z","host":"","path":"C:\\temp\\cAll\\SharePoint\\SP2013FOUND-20150304-1549_regular - Copy.log","tags":[],"parsedtime":"03/04/2015 15:49:43.01","process":"w3wp.exe","processcode":"0x1B48","tid":"0x1654","area":"SharePoint Foundation ","category":"Files ","eventID":"ak8dj","level":"High","eventmessage":"UserAgent not available, file operations may not be optimized...","CorrelationID":"0577ef9c-e7bf-402c-ea87-f8ab50bf959f"}
> {"message":"03/04/2015 15:49:43.01*\tw3wp.exe (0x1B48) \t0x1654\tSharePoint Foundation \tFiles \tak8dj\tHigh \t...) at Microsoft.SharePoint.Library...\t0577ef9c-e7bf-402c-ea87-f8ab50bf959f\r","@version":"1","@timestamp":"2015-08-03T14:14:51.994Z","host":"","path":"C:\\temp\\cAll\\SharePoint\\SP2013FOUND-20150304-1549_regular - Copy.log","tags":[],"parsedtime":"03/04/2015 15:49:43.01","multiline":"*","process":"w3wp.exe","processcode":"0x1B48","tid":"0x1654","area":"SharePoint Foundation ","category":"Files ","eventID":"ak8dj","level":"High","eventmessage":"...) at Microsoft.SharePoint.Library...","CorrelationID":"0577ef9c-e7bf-402c-ea87-f8ab50bf959f"}

```

Any idea how to isolate values from the field EventMessage and perform the requested operation, resulting with a single line with concatenated EventMessage field?

Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:33am UTC](https://discuss.elastic.co/t/how-to-perform-concatenation-of-values-from-the-same-field-in-multiple-lines/26729/2 "2017-07-06T05:33:04Z")

</div>


