# How to use Multiline codec and Json at the same time in a config file?

**URL:** <https://discuss.elastic.co/t/how-to-use-multiline-codec-and-json-at-the-same-time-in-a-config-file/85692>\
**Category:** Logstash\
**Created:** [May 14, 2017, 9:19pm UTC](https://discuss.elastic.co/t/how-to-use-multiline-codec-and-json-at-the-same-time-in-a-config-file/85692 "2017-05-14T21:19:10Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![amruth](https://avatars.discourse-cdn.com/v4/letter/a/43a26b/32.png) [@amruth](https://discuss.elastic.co/u/amruth)\
**Post date:** [May 14, 2017, 9:19pm UTC](https://discuss.elastic.co/t/how-to-use-multiline-codec-and-json-at-the-same-time-in-a-config-file/85692/1 "2017-05-14T21:19:10Z")

</div>

Hi, I have logs in the following format,

{  
"Name": "xxx",  
"Profession": "Developer",  
"Designation": "Senior",  
"StartDate": "20170317",  
"Salary": "xxxx"  
} {  
"Name": "xxx",  
"Profession": "Programmer",  
"Designation": "Junior",  
"StartDate": "20170519",  
"Salary": "xxxx"  
}

Basically, I am looking to consider each Json message as single event. I have a config file with multiline codec but after that I don't know how to consider that as Json event so that I can read input based on the field names. Can someone shed light on this?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 14, 2017, 10:58pm UTC](https://discuss.elastic.co/t/how-to-use-multiline-codec-and-json-at-the-same-time-in-a-config-file/85692/2 "2017-05-14T22:58:34Z")

</div>

What's your current config look like?

---

<div class="post-metadata">

**Author:** ![amruth](https://avatars.discourse-cdn.com/v4/letter/a/43a26b/32.png) [@amruth](https://discuss.elastic.co/u/amruth)\
**Post date:** [May 15, 2017, 2:55am UTC](https://discuss.elastic.co/t/how-to-use-multiline-codec-and-json-at-the-same-time-in-a-config-file/85692/3 "2017-05-15T02:55:11Z")

</div>

Hi Warkolm, here is my config file

input{  
file {  
path=\>"E:/Ex.log"  
codec =\> multiline {  
pattern =\> "}"  
negate =\> true  
what =\> previous  
}  
}  
}  
filter {  
if [message] =~ /^{.\*}$/ {  
json { source =\> message }  
}  
}  
output{  
stdout {  
codec=\>rubydebug  
}  
}

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [May 15, 2017, 5:40am UTC](https://discuss.elastic.co/t/how-to-use-multiline-codec-and-json-at-the-same-time-in-a-config-file/85692/4 "2017-05-15T05:40:32Z")

</div>

It looks like you have a single line that contains both the closing brace of one JSON object as well as the opening brace of the next. This means that this line would need to be split and included in both, which is not possible with a multiline pattern. You may need to gather the multiline objects and then do some post-processing to clean up/add/remove braces.

---

<div class="post-metadata">

**Author:** ![amruth](https://avatars.discourse-cdn.com/v4/letter/a/43a26b/32.png) [@amruth](https://discuss.elastic.co/u/amruth)\
**Post date:** [May 15, 2017, 2:58pm UTC](https://discuss.elastic.co/t/how-to-use-multiline-codec-and-json-at-the-same-time-in-a-config-file/85692/5 "2017-05-15T14:58:55Z")

</div>

Hi Christian, I've changed my input file so that it looks like,

{  
"Name": "xxx",  
"Profession": "Developer",  
"Designation": "Senior",  
"StartDate": "20170317",  
"Salary": "xxxx"  
}  
{  
"Name": "xxx",  
"Profession": "Programmer",  
"Designation": "Junior",  
"StartDate": "20170519",  
"Salary": "xxxx"  
}

And my config file is the same which I've mentioned above but the output is weird,

{  
"path" =\> "E:/Ex.log",  
"@timestamp" =\> 2017-05-15T14:44:34.982Z,  
"@version" =\> "1",  
"host" =\> "xxxx",  
"message" =\> "{\r"  
}  
{  
"path" =\> "E:/Ex.log",  
"@timestamp" =\> 2017-05-15T14:44:34.982Z,  
"@version" =\> "1",  
"host" =\> "xxxx",  
"message" =\> "\t"Name": "xxx",\r"  
}  
{  
"path" =\> "E:/Ex.log",  
"@timestamp" =\> 2017-05-15T14:44:34.982Z,  
"@version" =\> "1",  
"host" =\> "xxxx",  
"message" =\> "\t"Profession": "Developer",\r"  
}  
{  
"path" =\> "E:/Ex.log",  
"@timestamp" =\> 2017-05-15T14:44:34.982Z,  
"@version" =\> "1",  
"host" =\> "xxxx",  
"message" =\> "\t"Designation": "Senior",\r"  
}  
{  
"path" =\> "E:/Ex.log",  
"@timestamp" =\> 2017-05-15T14:44:34.982Z,  
"@version" =\> "1",  
"host" =\> "xxxx",  
"message" =\> "\t"Salary": "xxx",\r"  
}

Could you please help me with this?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 12, 2017, 3:09pm UTC](https://discuss.elastic.co/t/how-to-use-multiline-codec-and-json-at-the-same-time-in-a-config-file/85692/6 "2017-06-12T15:09:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
