# How to retrieve n number of previous lines in log file using logstash configuration?

**URL:** <https://discuss.elastic.co/t/how-to-retrieve-n-number-of-previous-lines-in-log-file-using-logstash-configuration/153350>\
**Category:** Logstash\
**Created:** [October 22, 2018, 8:53am UTC](https://discuss.elastic.co/t/how-to-retrieve-n-number-of-previous-lines-in-log-file-using-logstash-configuration/153350 "2018-10-22T08:53:35Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Vyankatesh\_S\_Repal](https://avatars.discourse-cdn.com/v4/letter/v/c77e96/32.png) [@Vyankatesh\_S\_Repal](https://discuss.elastic.co/u/Vyankatesh_S_Repal)\
**Post date:** [October 22, 2018, 8:53am UTC](https://discuss.elastic.co/t/how-to-retrieve-n-number-of-previous-lines-in-log-file-using-logstash-configuration/153350/1 "2018-10-22T08:53:36Z")

</div>

I am creating an application where I need to put previous and after n number of lines in elasticsearch with current log. This is my current logstash configuraion.  
What changes I need to make so that I can retrieve last n number of lines(Let's say 5) in my output?

```
input{ file{ path => "D:\ELK_Info\TestLogs_Updated.log"
#start_position => beginning
    ignore_older => 0
    sincedb_path => "NUL"
        codec => multiline {
                               pattern => "^%{TIMESTAMP_ISO8601}"
                               negate => true
                               what => "previous"
        } } }

filter{
    grok{
       match => {
      "message" => "%{TIMESTAMP_ISO8601:log_timestamp} %{DATA:line_number} %{DATA:log_level} %{DATA:log_type} %{NOTSPACE:space} %{GREEDYDATA:stackTrace}" } } mutate { remove_field => ["tags", "space", "line_number"]} }

output { file{ path => "D:\ELK_Info\logstashOutput.log" }
```

---

<div class="post-metadata">

**Author:** ![redX](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/redx/32/21864_2.png) [@redX](https://discuss.elastic.co/u/redX)\
**Post date:** [October 24, 2018, 7:42am UTC](https://discuss.elastic.co/t/how-to-retrieve-n-number-of-previous-lines-in-log-file-using-logstash-configuration/153350/2 "2018-10-24T07:42:26Z")

</div>

Can you give an example of the file `TestLogs_Updated.log`?  
What do you mean previous and after n number of lines?  
How the multiline codec works if it searches the pattern and takes as many lines until the pattern appears again. Do you have such a pattern in your log?

---

<div class="post-metadata">

**Author:** ![Vyankatesh\_S\_Repal](https://avatars.discourse-cdn.com/v4/letter/v/c77e96/32.png) [@Vyankatesh\_S\_Repal](https://discuss.elastic.co/u/Vyankatesh_S_Repal)\
**Post date:** [October 30, 2018, 5:19am UTC](https://discuss.elastic.co/t/how-to-retrieve-n-number-of-previous-lines-in-log-file-using-logstash-configuration/153350/3 "2018-10-30T05:19:37Z")

</div>

@redX  
Consider that current log starts from {TIMESTAMP\_ISO8601} but previous lines will not have any particular structure.  
Can we just retrieve n number of previous lines from this current log?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 27, 2018, 5:19am UTC](https://discuss.elastic.co/t/how-to-retrieve-n-number-of-previous-lines-in-log-file-using-logstash-configuration/153350/4 "2018-11-27T05:19:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
