# Java stack trace - Multiline config

**URL:** <https://discuss.elastic.co/t/java-stack-trace-multiline-config/247889>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [September 8, 2020, 12:22pm UTC](https://discuss.elastic.co/t/java-stack-trace-multiline-config/247889 "2020-09-08T12:22:25Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![sidiney.crescencio](https://avatars.discourse-cdn.com/v4/letter/s/2acd7d/32.png) [@sidiney.crescencio](https://discuss.elastic.co/u/sidiney.crescencio)\
**Post date:** [September 8, 2020, 12:22pm UTC](https://discuss.elastic.co/t/java-stack-trace-multiline-config/247889/1 "2020-09-08T12:22:26Z")

</div>

Hello,

I'm trying to configure a multiline pattern to get any exceptions in my application logs, unfortunately I haven't been able yet to find a good pattern.

Sample logs

```auto
2020-09-08 13:24:13.406 INFO 17739 --- [] c.o.insights.queries.QueryBuilder : builder with query took 9199 ms, adding missing items and sorting took 0 ms, total results 16
2020-09-08 13:24:13.412 INFO 17739 --- [] c.o.insights.queries.QueryBuilder : builder with query took 9204 ms, adding missing items and sorting took 1 ms, total results 16
2020-09-08 13:24:13.413 INFO 17739 --- [fa5f52a422c550c6 136.243.153.4 username] c.o.i.services.AggregatedResultsService : Received 56 results from the queryBuilder to convert to AggregatedChannelResults
2020-09-08 13:24:13.413 INFO 17739 --- [fa5f52a422c550c6 136.243.153.4 username] c.o.i.controllers.ChannelController : returning 56 channels
2020-09-08 13:24:13.416 ERROR 17739 --- [fa5f52a422c550c6 136.243.153.4 username] c.o.i.c.e.CustomRestExceptionHandler : error occurred

org.apache.catalina.connector.ClientAbortException: java.io.IOException: Broken pipe
        at org.apache.catalina.connector.OutputBuffer.doFlush(OutputBuffer.java:299)
        at org.apache.catalina.connector.OutputBuffer.flush(OutputBuffer.java:262)
        at org.apache.catalina.connector.CoyoteOutputStream.flush(CoyoteOutputStream.java:118)
        at org.springframework.security.web.util.OnCommittedResponseWrapper$SaveContext

2020-09-08 13:49:41.887 ERROR 1531 --- [659da38bae4e106f 2001:1c04:4807:f500:1084:70cc:970c:f492 username] c.o.insights.controllers.UserController : update.phoneNumber: Phone number can only contain numbers.

javax.validation.ConstraintViolationException: update.phoneNumber: Phone number can only contain numbers.
        at org.springframework.validation.beanvalidation.MethodValidationInterceptor.invoke(MethodValidationInterceptor.java:116)
        at org.springframework.aop.framework.ReflectiveMethodInvocation.proceed(ReflectiveMethodInvocation.java:186)
        at org.springframework.security.access.intercept.aopalliance.MethodSecurityInterceptor.invoke(MethodSecuri

```

My configuration :

```auto
- type: log
  paths:
    - /var/log/insights*.log
  scan_frequency: 60s
  multiline.type: pattern
  multiline.pattern: '^[0-9]{4}-[0-9]{2}-[0-9]{2} [0-9]{2}:[0-9]{2}:[0-9]{2}.[0-9]{3} (ERROR*)' 
  multiline.negate: false
  multiline.match: before
  multiline.max_lines: 50

```

I have already tried different combinations for the negate/match configs, but it didn't help. Basically I want to have for example, the next 50 lines once there is a ERROR message, I'm able to get the first line, for example below, but not the following lines.

```auto
2020-09-08 13:49:41.887 ERROR 1531 --- [659da38bae4e106f 2001:1c04:4807:f500:1084:70cc:970c:f492 username] c.o.insights.controllers.UserController : update.phoneNumber: Phone number can only contain numbers.

```

I think I cannot really apply a different pattern such as "caused by" because sometimes we do have errors, but not the "Caused by"

Could someone please advise ?

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 6, 2020, 2:22pm UTC](https://discuss.elastic.co/t/java-stack-trace-multiline-config/247889/2 "2020-10-06T14:22:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
