# Issue with logstash configuration for log file having mix of multiline as well as single level events

**URL:** <https://discuss.elastic.co/t/issue-with-logstash-configuration-for-log-file-having-mix-of-multiline-as-well-as-single-level-events/2381>\
**Category:** Logstash\
**Created:** [June 10, 2015, 8:02pm UTC](https://discuss.elastic.co/t/issue-with-logstash-configuration-for-log-file-having-mix-of-multiline-as-well-as-single-level-events/2381 "2015-06-10T20:02:10Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![chaitanyavvs](https://avatars.discourse-cdn.com/v4/letter/c/46a35a/32.png) [@chaitanyavvs](https://discuss.elastic.co/u/chaitanyavvs)\
**Post date:** [June 10, 2015, 8:02pm UTC](https://discuss.elastic.co/t/issue-with-logstash-configuration-for-log-file-having-mix-of-multiline-as-well-as-single-level-events/2381/1 "2015-06-10T20:02:11Z")

</div>

Hi ,  
I am newbie to logstash and i am using logstash 1.5.0. I have a log file (which is a historical log file ,as of now). I have written the following configuration. however i am unable to get any values. I have used the Grok Debugger to test the data and there were matches.

Update: I notice that whenever the file is changed, the filtering is activated and reading the file from beginning. However, if the file is historical, no new changes would be made. How do we make Logstash to read the entire file from beginning (i have specified the `start_position` to beginning.

Log File format :

> 04/15/15 18:40-XYZ-WARNING: Some Data  
> 04/15/15 18:40-XYZ-WARNING: Some Data  
> 04/15/15 18:40-XYZ-WARNING: Some Data  
> More Data on a new line. This line is a part of the previous line

I have the following config

> input{  
> file {  
> path =\> "C:/a.log"  
> type =\> "syslog"  
> start\_position =\> "beginning"  
> sincedb\_path=\>null  
> codec =\> multiline {  
> pattern =\> "^%{DATE}"  
> negate =\> true  
> what =\> previous  
> }  
> }  
> }

> filter {  
> grok {  
> match =\> { "message" =\> "%{DATE}%{SPACE}(?%{HOUR}:%{MINUTE})-(?%{WORD}-%{LOGLEVEL}):%{GREEDYDATA}" }  
> }  
> }

> output {  
> stdout {}  
> }

However i am unable to get any output matching. Request your help in letting me know where i am getting things wrong. Any pointers would be helpful

Thanks and Regards,  
Chaitanya V

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 10, 2015, 10:05pm UTC](https://discuss.elastic.co/t/issue-with-logstash-configuration-for-log-file-having-mix-of-multiline-as-well-as-single-level-events/2381/2 "2015-06-10T22:05:42Z")

</div>

This is a sincedb issue, if Logstash has seen the file at any point in time it will never go back the beginning of the file despite `start_position` being set.  
Delete the since.db file and you should be good.

If you are testing this file continually it's best to use stdin and then pipe the file into LS.

---

<div class="post-metadata">

**Author:** ![chaitanyavvs](https://avatars.discourse-cdn.com/v4/letter/c/46a35a/32.png) [@chaitanyavvs](https://discuss.elastic.co/u/chaitanyavvs)\
**Post date:** [June 11, 2015, 2:19pm UTC](https://discuss.elastic.co/t/issue-with-logstash-configuration-for-log-file-having-mix-of-multiline-as-well-as-single-level-events/2381/3 "2015-06-11T14:19:00Z")

</div>

Thanks a lot for the prompt reply @warkolm . I have deleted the sincedb file on the my login user folder and things started working well.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:37am UTC](https://discuss.elastic.co/t/issue-with-logstash-configuration-for-log-file-having-mix-of-multiline-as-well-as-single-level-events/2381/4 "2017-07-06T05:37:41Z")

</div>


