# Issue with file input multiline codec

**URL:** <https://discuss.elastic.co/t/issue-with-file-input-multiline-codec/66269>\
**Category:** Logstash\
**Created:** [November 16, 2016, 4:50pm UTC](https://discuss.elastic.co/t/issue-with-file-input-multiline-codec/66269 "2016-11-16T16:50:27Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![sjivan](https://avatars.discourse-cdn.com/v4/letter/s/c57346/32.png) [@sjivan](https://discuss.elastic.co/u/sjivan)\
**Post date:** [November 16, 2016, 4:50pm UTC](https://discuss.elastic.co/t/issue-with-file-input-multiline-codec/66269/1 "2016-11-16T16:50:27Z")

</div>

Hi,  
I have a log file that has I need to support multiline parsing and I'm in the process of migrating from multiline filter to multiline codec

My input configuration is

```
file {
    path => "c:/temp/test.log"
    start_position => beginning
    sincedb_path => "NUL"
    ignore_older => 0
    codec => multiline {
        pattern => "^%{MONTHDAY} %{MONTH} %{YEAR} %{TIME}"
        negate => true
        what => previous
    }       
}

```

When the log file has

```
28 Oct 2016 19:35:48:Log Message 1
28 Oct 2016 19:35:48:Log Message 2

```

the output containts only the first message

```
{
          "path" => "c:/temp/test.log",
    "@timestamp" => 2016-11-16T16:44:07.738Z,
      "@version" => "1",
          "host" => "myhost",
       "message" => "28 Oct 2016 19:35:48:Log Message 1\r",
          "tags" => []
}

```

When the log file has

```
28 Oct 2016 19:35:48:Log Message 1
28 Oct 2016 19:35:48:Log Message 2
28 Oct 2016 19:35:48:Log Message 3a
   Message 3b
28 Oct 2016 19:35:48:Log Message 4

```

the output has the first three messages but is missing Message 4

```
{
          "path" => "c:/temp/test.log",
    "@timestamp" => 2016-11-16T16:45:13.398Z,
      "@version" => "1",
          "host" => "myhost",
       "message" => "28 Oct 2016 19:35:48:Log Message 1\r",
          "tags" => []
}
{
          "path" => "c:/temp/test.log",
    "@timestamp" => 2016-11-16T16:45:13.403Z,
      "@version" => "1",
          "host" => "myhost",
       "message" => "28 Oct 2016 19:35:48:Log Message 2\r",
          "tags" => []
}
{
          "path" => "c:/temp/test.log",
    "@timestamp" => 2016-11-16T16:45:13.404Z,
      "@version" => "1",
          "host" => "myhost",
       "message" => "28 Oct 2016 19:35:48:Log Message 3a\r\n Message 3b\r",
          "tags" => [
        [0] "multiline"
    ]
}

```

Any suggestions would be appreciated.

Using LS 5.0

Thanks,  
Sanjiv

---

<div class="post-metadata">

**Author:** ![sjivan](https://avatars.discourse-cdn.com/v4/letter/s/c57346/32.png) [@sjivan](https://discuss.elastic.co/u/sjivan)\
**Post date:** [November 17, 2016, 12:48pm UTC](https://discuss.elastic.co/t/issue-with-file-input-multiline-codec/66269/2 "2016-11-17T12:48:41Z")

</div>

I found a related issue [https://github.com/logstash-plugins/logstash-input-file/issues/90](https://github.com/logstash-plugins/logstash-input-file/issues/90) which mentions that auto\_flush needs to be set via the auto\_flush\_interval codec parameter. Once I set auto\_flush\_interval =\> 3 I observed the desired behavior.

```
file {
    path => "c:/temp/test.log"
    start_position => beginning
    sincedb_path => "NUL"
    ignore_older => 0
    codec => multiline {
        pattern => "^%{MONTHDAY} %{MONTH} %{YEAR} %{TIME}"
        negate => true
        what => previous
        auto_flush_interval => 3
    }       
}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 15, 2016, 12:48pm UTC](https://discuss.elastic.co/t/issue-with-file-input-multiline-codec/66269/3 "2016-12-15T12:48:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
