# If make same head Multiline codec

**URL:** <https://discuss.elastic.co/t/if-make-same-head-multiline-codec/164227>\
**Category:** Logstash\
**Created:** [January 15, 2019, 3:01am UTC](https://discuss.elastic.co/t/if-make-same-head-multiline-codec/164227 "2019-01-15T03:01:45Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![jamespb](https://avatars.discourse-cdn.com/v4/letter/j/4da419/32.png) [@jamespb](https://discuss.elastic.co/u/jamespb)\
**Post date:** [January 15, 2019, 3:01am UTC](https://discuss.elastic.co/t/if-make-same-head-multiline-codec/164227/1 "2019-01-15T03:01:45Z")

</div>

I would like to make if beginning of 63 chars the same to be same document. For example if following 8 lines start with  
"2018/11/14-15:14:14.518292-09855-09855-432638034320556033-004-"  
is one doc, if logstash find a new line is not start with that, create a new document.

Thanks

=======================================================================  
2018/11/14-15:14:14.518292-09855-09855-432638034320556033-004- Sapi  
2018/11/14-15:14:14.518292-09855-09855-432638034320556033-004- \*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*  
2018/11/14-15:14:14.518292-09855-09855-432638034320556033-004- SAPI: internal message \<332\> processing begin ...  
2018/11/14-15:14:14.518292-09855-09855-432638034320556033-004- ====================  
2018/11/14-15:14:14.518292-09855-09855-432638034320556033-004- 0x7f733f8bc530  
2018/11/14-15:14:14.518292-09855-09855-432638034320556033-004- --------------------------------------------  
2018/11/14-15:14:14.518292-09855-09855-432638034320556033-004-  
2018/11/14-15:14:14.518292-09855-09855-432638034320556033-004- ====================  
2018/11/14-15:14:14.518298-09855-09855-432638034320556033-004- Sapi PPI set as:  
2018/11/14-15:14:14.518311-09855-09855-432638034320556035-004- Reading cache entry for ctx\_id : d900000a0f380002  
2018/11/14-15:14:14.518319-09855-09855-432638034320556035-004- Pers-Mgr PersistentObject constructed as: 0x7f618656dac0

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 15, 2019, 3:52pm UTC](https://discuss.elastic.co/t/if-make-same-head-multiline-codec/164227/2 "2019-01-15T15:52:46Z")

</div>

Those 8 lines do not start with the same 63 characters. The last 3 have different time stamps. That said, if we break off the timestamp and then use the rest of the 63 you can do it using aggregate.

```
grok { match => { "message" => ["^(?<time>.{26})(?<taskId>.{37})"] } }
aggregate {
    task_id => "%{taskId}"
    code => "map['message'] ||= ''; map['message'] += event.get('message') + '
';"
    push_map_as_event_on_timeout => true
    timeout_task_id_field => "taskId"
    timeout => 2 # 2s timeout
    timeout_code => "event.set('[@metadata][wanted]', 1)"
}
if [@metadata][wanted] != 1 { drop {} }
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 12, 2019, 3:52pm UTC](https://discuss.elastic.co/t/if-make-same-head-multiline-codec/164227/3 "2019-02-12T15:52:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
