# Log parsing issue

**URL:** <https://discuss.elastic.co/t/log-parsing-issue/289306>\
**Category:** Logstash\
**Created:** [November 16, 2021, 10:53am UTC](https://discuss.elastic.co/t/log-parsing-issue/289306 "2021-11-16T10:53:12Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Divya\_Bansal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/divya_bansal/32/81564_2.png) [@Divya\_Bansal](https://discuss.elastic.co/u/Divya_Bansal)\
**Post date:** [November 16, 2021, 10:53am UTC](https://discuss.elastic.co/t/log-parsing-issue/289306/1 "2021-11-16T10:53:12Z")

</div>

**I am having a log in the following format:-**

```auto
{"@timestamp":"2021-08-04T09:57:25.141Z","@metadata":{"beat":"filebeat","type":"_doc","version":"7.6.3"},"log":{"offset":10413931,"file":{"path":"api/api.log"}},"message":"[ERROR] 2021-10-18T22:36:04.672 [http-nio2-8080-exec-48] [FTDS] deployment-75bf886778-gj8hv - [i.i.i.a.e.f.s.ManageForm] :: RuntimeException is caught with error code: ITB-EXEC2003 and DevMessage: null and UserMessage: Due to some technical error not able to process.Please check corresponding class 
	   and error code ITB-EXEC2003 and stacktrace: java.lang.NullPointerException
	at in.it.ic.api.filing.form.FormData.validateAndSet(FormData.java:858)
	at in.it.ic.api.filing.form.FormData.setFeilds(FormData.java:822)
	at jdk.internal.reflect.GeneratedMethodAccessor304.invoke(Unknown Source)
	at java.base/jdk.internal.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)
	at java.base/java.lang.reflect.Method.invoke(Method.java:566)
	at org.springframework.aop.support.AopUtils.invokeJoinpointUsingReflection(AopUtils.java:344)
	at org.springframework.aop.framework.ReflectiveMethodInvocation.invokeJoinpoint(ReflectiveMethodInvocation.java:198)
	at org.springframework.aop.framework.ReflectiveMethodInvocation.proceed(ReflectiveMethodInvocation.java:163)
	at org.springframework.transaction.interceptor.TransactionInterceptor$$Lambda$510/00000000046D7C60.proceedWithInvocation(Unknown Source)
	at org.springframework.transaction.interceptor.TransactionAspectSupport.invokeWithinTransaction(TransactionAspectSupport.java:366)
	at org.springframework.transaction.interceptor.TransactionInterceptor.invoke(TransactionInterceptor.java:99)
	at org.springframework.aop.framework.ReflectiveMethodInvocation.proceed(ReflectiveMethodInvocation.java:186)
	at org.springframework.aop.framework.JdkDynamicAopProxy.invoke(JdkDynamicAopProxy.java:212)
	at com.sun.proxy.$Proxy135.serve(Unknown Source)
	at org.springframework.aop.aspectj.MethodInvocationProceedingJoinPoint.proceed(MethodInvocationProceedingJoinPoint.java:88)
	at jdk.internal.reflect.GeneratedMethodAccessor247.invoke(Unknown Source)
	at java.base/jdk.internal.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)
	at java.base/java.lang.reflect.Method.invoke(Method.java:566)
	at org.springframework.aop.aspectj.AbstractAspectJAdvice.invokeAdviceMethodWithGivenArgs(AbstractAspectJAdvice.java:644)
	at org.springframework.aop.aspectj.AbstractAspectJAdvice.invokeAdviceMethod(AbstractAspectJAdvice.java:633)
	at org.springframework.aop.aspectj.AspectJAroundAdvice.invoke(AspectJAroundAdvice.java:70)
	at org.springframework.aop.framework.ReflectiveMethodInvocation.proceed(ReflectiveMethodInvocation.java:186)
	at org.springframework.aop.framework.CglibAopProxy$CglibMethodInvocation.proceed(CglibAopProxy.java:747)
	at org.springframework.aop.interceptor.ExposeInvocationInterceptor.invoke(ExposeInvocationInterceptor.java:93)
	at org.springframework.aop.framework.ReflectiveMethodInvocation.proceed(ReflectiveMethodInvocation.java:186)
	at org.springframework.aop.framework.CglibAopProxy$CglibMethodInvocation.proceed(CglibAopProxy.java:747)
	at org.springframework.aop.framework.CglibAopProxy$DynamicAdvisedInterceptor.intercept(CglibAopProxy.java:689)
	at jdk.internal.reflect.GeneratedMethodAccessor246.invoke(Unknown Source)
	at java.base/jdk.internal.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)
	at java.base/java.lang.reflect.Method.invoke(Method.java:566)
	at org.springframework.web.method.support.InvocableHandlerMethod.doInvoke(InvocableHandlerMethod.java:190)
	at org.springframework.web.method.support.InvocableHandlerMethod.invokeForRequest(InvocableHandlerMethod.java:138)
	at org.springframework.web.servlet.mvc.method.annotation.ServletInvocableHandlerMethod.invokeAndHandle(ServletInvocableHandlerMethod.java:106)
	at org.springframework.web.servlet.mvc.method.annotation.RequestMappingHandlerAdapter.invokeHandlerMethod(RequestMappingHandlerAdapter.java:888)
	at org.springframework.web.servlet.mvc.method.annotation.RequestMappingHandlerAdapter.handleInternal(RequestMappingHandlerAdapter.java:793)
	at org.springframework.web.servlet.mvc.method.AbstractHandlerMethodAdapter.handle(AbstractHandlerMethodAdapter.java:87)
	at org.springframework.web.servlet.DispatcherServlet.doDispatch(DispatcherServlet.java:1040)
	at org.springframework.web.servlet.DispatcherServlet.doService(DispatcherServlet.java:943)
	at org.springframework.web.servlet.FrameworkServlet.processRequest(FrameworkServlet.java:1006)
	at org.springframework.web.servlet.FrameworkServlet.doPost(FrameworkServlet.java:909)
	at javax.servlet.http.HttpServlet.service(HttpServlet.java:652)
	at org.springframework.web.servlet.FrameworkServlet.service(FrameworkServlet.java:883)
	at javax.servlet.http.HttpServlet.service(HttpServlet.java:733)
	at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:231)
	at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:166)
	at org.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:53)
	at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:193)
	at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:166)
	at org.apache.catalina.filters.HttpHeaderSecurityFilter.doFilter(HttpHeaderSecurityFilter.java:126)
	at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:193)
	at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:166)
	at org.apache.tomcat.util.threads.TaskThread$WrappingRunnable.run(TaskThread.java:61)
	at java.base/java.lang.Thread.run(Thread.java:836)
 and the possible root cause is java.lang.NullPointerException at 1634576764672 with objectarray values asnull[#]","input":{"type":"log"},"ecs":{"version":"1.4.0"},"host":{"mac":["/"],"hostname":"boot","architecture":"ppc64le","os":{"codename":"Maipo","platform":"rhel","version":"7.6 (Maipo)","family":"redhat","name":"Red Hat Enterprise Linux Server","kernel":"4.14.0-115.13.1.el7a.ppc64le"},"id":"4994b06b9b4248dd81e0c113f2221e54","name":"dcplicpboot","containerized":false,"ip":["/"]},"agent":{"version":"7.6.3","type":"filebeat","ephemeral_id":"e249728c-21f3-4ea6-be0f-b5ce5ff7447f","hostname":"boot","id":"6bd6e68b-3f3e-4985-8738-08b3488fffd7"}}

```

I wanted to parse the multiline message into single line in logstash. can anyone help me to do this?

---

<div class="post-metadata">

**Author:** ![Wolfram\_Haussig](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfram_haussig/32/70528_2.png) [@Wolfram\_Haussig](https://discuss.elastic.co/u/Wolfram_Haussig)\
**Post date:** [November 16, 2021, 11:28am UTC](https://discuss.elastic.co/t/log-parsing-issue/289306/2 "2021-11-16T11:28:51Z")

</div>

Hi,

What do you mean by `parse the multiline message into single line`? You want to remove the line breaks?

Best regards  
Wolfram

---

<div class="post-metadata">

**Author:** ![Divya\_Bansal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/divya_bansal/32/81564_2.png) [@Divya\_Bansal](https://discuss.elastic.co/u/Divya_Bansal)\
**Post date:** [November 16, 2021, 12:00pm UTC](https://discuss.elastic.co/t/log-parsing-issue/289306/3 "2021-11-16T12:00:14Z")

</div>

yes, all the different lines of stack trace should be considered as single line.

---

<div class="post-metadata">

**Author:** ![Wolfram\_Haussig](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfram_haussig/32/70528_2.png) [@Wolfram\_Haussig](https://discuss.elastic.co/u/Wolfram_Haussig)\
**Post date:** [November 16, 2021, 12:10pm UTC](https://discuss.elastic.co/t/log-parsing-issue/289306/4 "2021-11-16T12:10:21Z")

</div>

Although I have not tried the solution, I found one on stackoverflow: [elasticsearch - How to remove Newline from a log in filter block using mutate gsub - Stack Overflow](https://stackoverflow.com/questions/57786443/how-to-remove-newline-from-a-log-in-filter-block-using-mutate-gsub)

```auto
mutate{
    gsub => ["message", "\\n", ""]
  }

```

---

<div class="post-metadata">

**Author:** ![Divya\_Bansal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/divya_bansal/32/81564_2.png) [@Divya\_Bansal](https://discuss.elastic.co/u/Divya_Bansal)\
**Post date:** [November 16, 2021, 1:19pm UTC](https://discuss.elastic.co/t/log-parsing-issue/289306/5 "2021-11-16T13:19:33Z")

</div>

not worked

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 16, 2021, 6:00pm UTC](https://discuss.elastic.co/t/log-parsing-issue/289306/6 "2021-11-16T18:00:33Z")

</div>

You would use a multiline codec to combine the lines of the stack trace with the error message. The [documentation](https://www.elastic.co/guide/en/logstash/current/plugins-codecs-multiline.html) has an example that shows how to do that for Java stack traces.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 14, 2021, 6:01pm UTC](https://discuss.elastic.co/t/log-parsing-issue/289306/7 "2021-12-14T18:01:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
