# Logs files multi line filter (ASCII)

**URL:** <https://discuss.elastic.co/t/logs-files-multi-line-filter-ascii/58970>\
**Category:** Logstash\
**Created:** [August 25, 2016, 6:06pm UTC](https://discuss.elastic.co/t/logs-files-multi-line-filter-ascii/58970 "2016-08-25T18:06:26Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![Hans](https://avatars.discourse-cdn.com/v4/letter/h/e19b73/32.png) [@Hans](https://discuss.elastic.co/u/Hans)\
**Post date:** [August 25, 2016, 6:06pm UTC](https://discuss.elastic.co/t/logs-files-multi-line-filter-ascii/58970/1 "2016-08-25T18:06:26Z")

</div>

HI, I would like to find out if logstash can process multiple lines that are below each other? Here is an example of a log:  
{  
1=352621443221  
2=3525945678  
3=20140225132715  
4=345  
7=0  
8=  
9=  
10=  
11=ABC-1  
13=0  
16=0  
23=20140225132952  
40=350953203616  
41=356401660  
134=  
135=  
142=267341000053  
215=  
216=  
220=751236  
223=0  
225=  
226=  
227=85015  
229=  
236=  
237=0  
239=file.dat  
243=  
224=54862231580161  
253=0  
374=0  
385=0  
510=  
1314=0  
337=  
993=265873610053  
228=85469  
1328=266894230053  
1500=358549620  
1329=268546932153  
21=-1  
1370=  
1315=323456660  
}

The logs starts with the "{" and ends with the "}"

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 25, 2016, 6:12pm UTC](https://discuss.elastic.co/t/logs-files-multi-line-filter-ascii/58970/2 "2016-08-25T18:12:13Z")

</div>

Yes, you can probably use a multiline codec to join these lines. The configuration you're looking for is "unless the line begins with an opening or closing brace, join the current line with the previous line".

---

<div class="post-metadata">

**Author:** ![Hans](https://avatars.discourse-cdn.com/v4/letter/h/e19b73/32.png) [@Hans](https://discuss.elastic.co/u/Hans)\
**Post date:** [August 25, 2016, 6:18pm UTC](https://discuss.elastic.co/t/logs-files-multi-line-filter-ascii/58970/3 "2016-08-25T18:18:37Z")

</div>

Yes the logs has an opening "{" to indicate this is the log beginning and a "}" to show it is ending. This continues for every log record in the log file. so if there are 100 logs a log file each one of the 100 logs start with "{" and ends with "}". how would you define the "{" and "}" as deliminator for such a file?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 25, 2016, 6:31pm UTC](https://discuss.elastic.co/t/logs-files-multi-line-filter-ascii/58970/4 "2016-08-25T18:31:02Z")

</div>

This might work:

```nohighlight
input {
  file {
    path => ...
    codec => multiline {
      pattern => "^\{"
      what => "previous"
      negate => true
    }
  }
}

```

In other words, if the current line _doesn't_ begin with an opening brace, join with the previous line.

---

<div class="post-metadata">

**Author:** ![Hans](https://avatars.discourse-cdn.com/v4/letter/h/e19b73/32.png) [@Hans](https://discuss.elastic.co/u/Hans)\
**Post date:** [August 25, 2016, 6:38pm UTC](https://discuss.elastic.co/t/logs-files-multi-line-filter-ascii/58970/5 "2016-08-25T18:38:34Z")

</div>

Thank you for the example, so the files regarding brackets look like this:  
{  
.....  
.....  
.....  
}  
{  
.....  
.....  
.....  
}

And so it continues for the entire file, so it is only required to input the pattern with the opening bracket?

Is it still required to also have a filter section for this file?

---

<div class="post-metadata">

**Author:** ![Hans](https://avatars.discourse-cdn.com/v4/letter/h/e19b73/32.png) [@Hans](https://discuss.elastic.co/u/Hans)\
**Post date:** [August 25, 2016, 7:14pm UTC](https://discuss.elastic.co/t/logs-files-multi-line-filter-ascii/58970/6 "2016-08-25T19:14:39Z")

</div>

I have tried the following config however it does not produce any output:  
input {  
file {  
type =\> "DRIN"  
path =\> ["/ar\*DRIN"]  
codec =\> multiline {  
pattern =\> "^{"  
what =\> "previous"  
negate =\> true  
}  
}  
}

filter {  
grok {  
match =\> ["message", "%{GREEDYDATA:kvdata}"]  
}  
kv {  
field\_split =\> " "  
value\_split =\> "="  
source =\> "kvdata"  
remove\_field =\> "kvdata"  
}  
date {  
locale =\> "en"  
match =\> ["3", "yyyyMMddHHmmss", "ISO8601"]  
timezone =\> "Africa/Windhoek"  
target =\> "@timestamp"  
add\_field =\> { "debug" =\> "timestampMatched"}  
}

}

output {  
elasticsearch {  
hosts =\> "localhost:9200"  
index =\> "%{logstash}-%{+YYYY.MM.dd}"  
}  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 25, 2016, 8:27pm UTC](https://discuss.elastic.co/t/logs-files-multi-line-filter-ascii/58970/7 "2016-08-25T20:27:25Z")

</div>

> And so it continues for the entire file, so it is only required to input the pattern with the opening bracket?

Yes. Understanding how the multiline codec is supposed to work is essential.

> Is it still required to also have a filter section for this file?

If you want to parse the data further, yes.

> I have tried the following config however it does not produce any output:

That's because Logstash is tailing the file. Read about sincedb in the file input documentation and study the `start_position`, `sincedb_path`, and `ignore_older` options.

---

<div class="post-metadata">

**Author:** ![Hans](https://avatars.discourse-cdn.com/v4/letter/h/e19b73/32.png) [@Hans](https://discuss.elastic.co/u/Hans)\
**Post date:** [August 25, 2016, 10:26pm UTC](https://discuss.elastic.co/t/logs-files-multi-line-filter-ascii/58970/8 "2016-08-25T22:26:43Z")

</div>

Thank you very much I got it to work, much appreciated the assistance.

---

<div class="post-metadata">

**Author:** ![Hans](https://avatars.discourse-cdn.com/v4/letter/h/e19b73/32.png) [@Hans](https://discuss.elastic.co/u/Hans)\
**Post date:** [August 30, 2016, 6:37pm UTC](https://discuss.elastic.co/t/logs-files-multi-line-filter-ascii/58970/9 "2016-08-30T18:37:45Z")

</div>

I have one more question regarding the fields, the initial field descriptor is a number e.g.

{  
1=352621443221  
2=3525945678  
.......

so the leading numbers have a description, how do I add these as descriptors e.g.  
1 is Calling\_Number  
2 is Called\_Number  
......

I thought of using the translate plugin however then I have to have one for each field as there are around 1000 of them. Your assistance will be appreciated.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 30, 2016, 7:14pm UTC](https://discuss.elastic.co/t/logs-files-multi-line-filter-ascii/58970/10 "2016-08-30T19:14:02Z")

</div>

I don't see how you could get around listing all 1000 possible values in a table somewhere.

---

<div class="post-metadata">

**Author:** ![Hans](https://avatars.discourse-cdn.com/v4/letter/h/e19b73/32.png) [@Hans](https://discuss.elastic.co/u/Hans)\
**Post date:** [August 30, 2016, 7:16pm UTC](https://discuss.elastic.co/t/logs-files-multi-line-filter-ascii/58970/11 "2016-08-30T19:16:22Z")

</div>

Ok, so a rename list would most probably do the trick, correct?  
e.g.  
mutate {  
rename =\> { "1" =\> "Calling\_Number" }  
rename =\> { "2" =\> "Called\_Number" }  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 30, 2016, 7:46pm UTC](https://discuss.elastic.co/t/logs-files-multi-line-filter-ascii/58970/12 "2016-08-30T19:46:10Z")

</div>

Yes, if the translate filter can't help out.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:40am UTC](https://discuss.elastic.co/t/logs-files-multi-line-filter-ascii/58970/13 "2017-07-06T04:40:48Z")

</div>


