# Kibana break message into multiple line

**URL:** <https://discuss.elastic.co/t/kibana-break-message-into-multiple-line/117355>\
**Category:** Elasticsearch\
**Created:** [January 28, 2018, 11:21am UTC](https://discuss.elastic.co/t/kibana-break-message-into-multiple-line/117355 "2018-01-28T11:21:23Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Farhad\_Yousefi](https://avatars.discourse-cdn.com/v4/letter/f/b487fb/32.png) [@Farhad\_Yousefi](https://discuss.elastic.co/u/Farhad_Yousefi)\
**Post date:** [January 28, 2018, 11:21am UTC](https://discuss.elastic.co/t/kibana-break-message-into-multiple-line/117355/1 "2018-01-28T11:21:24Z")

</div>

I want to monitor "messages" and my application log. For doing that I define two pattern in grok (one for messages and other for my exception in application)

```
    filter {
      if [type] == "log" {
        grok {
          match => { "message" => [
"%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{DATA:syslog_program}(?:\[%{POSINT:syslog_pid}\])?: %{GREEDYDATA:syslog_message}" ,
          "(Exception in \*\*\*) (?<Level>.*)(\*\*\* occured.\nDate&Time: )%{TIMESTAMP_ISO8601:timestamp}\n(Root:)(?<Message.Root>(.|\r|\n)*[^\*]{5,})
((\*|\n)*)(ExceptionList:)(?<Message.ExceptionList>(.|\r|\n)*)"
          ]
          }
          add_field => ["received_at", "%{@timestamp}"]
          add_field => ["received_from", "%{host}"]
        }
        syslog_pri { }
        date {
          match => ["syslog_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]
        }
      }
    }

```

and it is my elastic index pattern:

```
  "mappings": {
    "_default_": {
      "_all": {
        "enabled": true,
        "norms": {
          "enabled": false
        }
      },
      "dynamic_templates": [
        {
          "template1": {
            "mapping": {
              "doc_values": true,
              "ignore_above": 50000,
              "index": "not_analyzed",
              "type": "{dynamic_type}"
            },
            "match": "*"
          }
        }
      ],
      "properties": {
        "@timestamp": {
          "type": "date"
        },
        "message": {
          "type": "string",
          "index": "analyzed"
        },
        "offset": {
          "type": "long",
          "doc_values": "true"
        },
        "geoip" : {
          "type" : "object",
          "dynamic": true,
          "properties" : {
            "location" : { "type" : "geo_point" }
          }
        }
      }
    }
  },
  "settings": {
    "index.refresh_interval": "2s"
  },
  "template": "filebeat-*"

```

kibana shows message from "messages file" load perfectly but about my specific log it break into multi line . what is my problems?  
thank you

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 25, 2018, 11:22am UTC](https://discuss.elastic.co/t/kibana-break-message-into-multiple-line/117355/2 "2018-02-25T11:22:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
