# Log file parsing and ingesting into ES

**URL:** <https://discuss.elastic.co/t/log-file-parsing-and-ingesting-into-es/247806>\
**Category:** Logstash\
**Created:** [September 7, 2020, 7:44pm UTC](https://discuss.elastic.co/t/log-file-parsing-and-ingesting-into-es/247806 "2020-09-07T19:44:03Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 7, 2020, 7:56pm UTC](https://discuss.elastic.co/t/log-file-parsing-and-ingesting-into-es/247806/2 "2020-09-07T19:56:27Z")

</div>

> [@ankitachow](#):
>
> [ERROR] 2020-09-07 14:38:58.833 [Converge PipelineAction::Create] agent - Failed to execute action {:id=\>:main, :action\_type=\>LogStash::ConvergeResult::FailedAction, :message=\>"Could not execute action: PipelineAction::Create, action\_result: false", :backtrace=\>nil}

What else is in the log file? I would expect there to be another ERROR message.

Your multiline configuration looks wrong to me. It will consume the first 4 lines as one event, then the first two event elements will be flushed as events, then the last two lines. How about

```
pattern => "</trouble_shooter_log>"
negate => true
what => next

```

---

_[View the full topic](https://discuss.elastic.co/t/log-file-parsing-and-ingesting-into-es/247806)._
