# Logstash 5.1.1 - Couldn't find any filter plugin named 'multiline'

**URL:** <https://discuss.elastic.co/t/logstash-5-1-1-couldnt-find-any-filter-plugin-named-multiline/71263>\
**Category:** Logstash\
**Created:** [January 11, 2017, 5:20pm UTC](https://discuss.elastic.co/t/logstash-5-1-1-couldnt-find-any-filter-plugin-named-multiline/71263 "2017-01-11T17:20:22Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![MikeSiz](https://avatars.discourse-cdn.com/v4/letter/m/b782af/32.png) [@MikeSiz](https://discuss.elastic.co/u/MikeSiz)\
**Post date:** [January 11, 2017, 5:20pm UTC](https://discuss.elastic.co/t/logstash-5-1-1-couldnt-find-any-filter-plugin-named-multiline/71263/1 "2017-01-11T17:20:22Z")

</div>

Hi, I am trying to migrate from logstash 2.3.4 to newer 5.1.1.  
After default installation (registering logstash 5.1 repo and yum install logstash)  
I found that logstash cannot find "multiline' plugin.

I tried:  
/usr/share/logstash/bin/logstash-plugin install logstash-codec-multiline

and it installed multiline successfully. Could see it in the list:

[root@xxxx logstash]# /usr/share/logstash/bin/logstash-plugin list | grep multil  
logstash-codec-multiline

However, it still cannot find it, when I try to check configuration:

[root@xxxx logstash]# sudo -u logstash /usr/share/logstash/bin/logstash --path.settings /etc/logstash -f /etc/logstash/conf.d/logstash.conf --config.test\_and\_exit

it raises the error in /var/log/logstash/logstash-plain.log:

[root@xxxx logstash]# more logstash-plain.log

[2017-01-11T10:08:11,674][ERROR][logstash.plugins.registry] Problems loading a plugin with {:type=\>"filter", :name=\>"multiline", :path=\>"logstash/filters/mult  
iline", :error\_message=\>"NameError", :error\_class=\>NameError,  
....

Could someone help me? What am I doing wrong?

Thanks,  
Michael

---

<div class="post-metadata">

**Author:** ![MikeSiz](https://avatars.discourse-cdn.com/v4/letter/m/b782af/32.png) [@MikeSiz](https://discuss.elastic.co/u/MikeSiz)\
**Post date:** [January 11, 2017, 5:42pm UTC](https://discuss.elastic.co/t/logstash-5-1-1-couldnt-find-any-filter-plugin-named-multiline/71263/2 "2017-01-11T17:42:48Z")

</div>

I have found the problem.

I should have been installing "filter", not a "codec"

/usr/share/logstash/bin/logstash-plugin install logstash-filter-multiline

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [January 11, 2017, 8:21pm UTC](https://discuss.elastic.co/t/logstash-5-1-1-couldnt-find-any-filter-plugin-named-multiline/71263/3 "2017-01-11T20:21:13Z")

</div>

You should probably try to migrate away from the multiline filter as it has been deprecated. It is generally recommended to perform this processing as close to the sources as possible. Filebeat supports this and if you need to do it in Logstash, the multiline codec is the recommended way to go.

---

<div class="post-metadata">

**Author:** ![MikeSiz](https://avatars.discourse-cdn.com/v4/letter/m/b782af/32.png) [@MikeSiz](https://discuss.elastic.co/u/MikeSiz)\
**Post date:** [January 18, 2017, 8:56pm UTC](https://discuss.elastic.co/t/logstash-5-1-1-couldnt-find-any-filter-plugin-named-multiline/71263/4 "2017-01-18T20:56:59Z")

</div>

Thank you, will look at it

---

<div class="post-metadata">

**Author:** ![seth.yes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/seth.yes/32/11788_2.png) [@seth.yes](https://discuss.elastic.co/u/seth.yes)\
**Post date:** [January 27, 2017, 7:36pm UTC](https://discuss.elastic.co/t/logstash-5-1-1-couldnt-find-any-filter-plugin-named-multiline/71263/5 "2017-01-27T19:36:51Z")

</div>

@Christian_Dahlqvist

It would be great if the multiline filter was marked as deprecated or just removed entirely from [the current documentation](https://www.elastic.co/guide/en/logstash/current/plugins-codecs-multiline.html).

 ![](https://us1.discourse-cdn.com/elastic/original/2X/1/1964bfc1ff2295d2ac4bd7127defeefed6ed843b.png)

edit: added screenshot

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [January 27, 2017, 8:43pm UTC](https://discuss.elastic.co/t/logstash-5-1-1-couldnt-find-any-filter-plugin-named-multiline/71263/6 "2017-01-27T20:43:52Z")

</div>

What you linked to is the multi line codec, not the multi line filter which has been deprecated. The multi line codec is still supported as it does not suffer from the limitations of the filter.

---

<div class="post-metadata">

**Author:** ![seth.yes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/seth.yes/32/11788_2.png) [@seth.yes](https://discuss.elastic.co/u/seth.yes)\
**Post date:** [January 27, 2017, 8:44pm UTC](https://discuss.elastic.co/t/logstash-5-1-1-couldnt-find-any-filter-plugin-named-multiline/71263/7 "2017-01-27T20:44:42Z")

</div>

Understood, however the screenshot shows the multiline filter, which makes the multiline filter appear as if it's still supported.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [January 27, 2017, 8:46pm UTC](https://discuss.elastic.co/t/logstash-5-1-1-couldnt-find-any-filter-plugin-named-multiline/71263/8 "2017-01-27T20:46:13Z")

</div>

Aha, did not notice that. We should get that corrected in that case.

---

<div class="post-metadata">

**Author:** ![seth.yes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/seth.yes/32/11788_2.png) [@seth.yes](https://discuss.elastic.co/u/seth.yes)\
**Post date:** [January 27, 2017, 11:03pm UTC](https://discuss.elastic.co/t/logstash-5-1-1-couldnt-find-any-filter-plugin-named-multiline/71263/9 "2017-01-27T23:03:53Z")

</div>

@Christian_Dahlqvist I'm not in a good place to edit the docs but if you get anyone to change it, someone should also add that apparently the 'auto\_flush\_interval' is required to make the multiline codec work. Thanks!

> [@Logstash input file codec multiline not working as expected](https://discuss.elastic.co/t/logstash-input-file-codec-multiline-not-working-as-expected/55913/4):
>
> For me setting auto\_flush\_interval =\> 5 does solve the problem.

> [@Issue with file input multiline codec](https://discuss.elastic.co/t/issue-with-file-input-multiline-codec/66269/2):
>
> I found a related issue [https://github.com/logstash-plugins/logstash-input-file/issues/90](https://github.com/logstash-plugins/logstash-input-file/issues/90) which mentions that auto\_flush needs to be set via the auto\_flush\_interval codec parameter. Once I set auto\_flush\_interval =\> 3 I observed the desired behavior. file { path =\> "c:/temp/test.log" start\_position =\> beginning sincedb\_path =\> "NUL" ignore\_older =\> 0 codec =\> multiline { pattern =\> "^%{MONTHDAY} %{MONTH} %{YEAR} %{TIME}" negate =\> true what =\> previou…

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [January 28, 2017, 8:29am UTC](https://discuss.elastic.co/t/logstash-5-1-1-couldnt-find-any-filter-plugin-named-multiline/71263/10 "2017-01-28T08:29:42Z")

</div>

I have opened an [issue](https://github.com/elastic/logstash-docs/issues/351) against the Github repository containing the Logstash documentation. I have also opened another [issue](https://github.com/logstash-plugins/logstash-codec-multiline/issues/50) against the multiline codec plugin to either set a default value or add additional information about the `auto_flush_interval` parameter and use to the documentation.

Thanks for pointing this out.

---

<div class="post-metadata">

**Author:** ![rlv\_praveen](https://avatars.discourse-cdn.com/v4/letter/r/97f17d/32.png) [@rlv\_praveen](https://discuss.elastic.co/u/rlv_praveen)\
**Post date:** [January 28, 2017, 11:42am UTC](https://discuss.elastic.co/t/logstash-5-1-1-couldnt-find-any-filter-plugin-named-multiline/71263/11 "2017-01-28T11:42:30Z")

</div>

I also faced the same error in logstash 5.1.2 version. multiline filter is removed from logstash 5._._ versions. you could please try the multiline codec filter instead.

You need to use the multiline codec in the input tag not in the filter tag. For sure your problem will be solved. Kudos try it and update us.

---

<div class="post-metadata">

**Author:** ![seth.yes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/seth.yes/32/11788_2.png) [@seth.yes](https://discuss.elastic.co/u/seth.yes)\
**Post date:** [January 30, 2017, 3:42pm UTC](https://discuss.elastic.co/t/logstash-5-1-1-couldnt-find-any-filter-plugin-named-multiline/71263/12 "2017-01-30T15:42:15Z")

</div>

Thanks for your response. I've implemented the codec and am still not getting any data pulled in through Logstash. I'll start another thread in an attempt to not further-hijack this thread.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 27, 2017, 3:42pm UTC](https://discuss.elastic.co/t/logstash-5-1-1-couldnt-find-any-filter-plugin-named-multiline/71263/13 "2017-02-27T15:42:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
