# Logstash 5.1 - Multiline codec with file input

**URL:** <https://discuss.elastic.co/t/logstash-5-1-multiline-codec-with-file-input/70635>\
**Category:** Logstash\
**Created:** [January 5, 2017, 5:17am UTC](https://discuss.elastic.co/t/logstash-5-1-multiline-codec-with-file-input/70635 "2017-01-05T05:17:59Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![spravn789](https://avatars.discourse-cdn.com/v4/letter/s/e47c2d/32.png) [@spravn789](https://discuss.elastic.co/u/spravn789)\
**Post date:** [January 5, 2017, 5:17am UTC](https://discuss.elastic.co/t/logstash-5-1-multiline-codec-with-file-input/70635/1 "2017-01-05T05:17:59Z")

</div>

Hi All,

I am using Logstash 5.1 , where facing issues with multiline, Since multiline filter is depricated, trying to use multiline codec along with file input.

In the response all the line are getting combined and facing error as in attached file,

PFB the config file and pattern, also sample log file for which used for testing. Also attached the kibana view and logstash log.

FYI, Same is working with multiline filter in earlier version. Logstash\_ log is showing few warning as in attachment and throwing grokparsefaiure and multiline tag.

Kindly help to resolve this.

_ **Pattern:** _\*\*\*

# Logstash pattent configuration

BWTIME %{YEAR} %{MONTH} %{MONTHDAY} %{TIME} GMT +%{INT}  
BWLOG %{BWTIME:timestamp} GMT +%{INT} %{GREEDYDATA:Bwpayload}

**Config File** \*\*

input {  
file {  
path =\> "E:/logs/\*.log"  
type =\> "esbbwlog"  
codec =\> multiline {  
patterns\_dir =\> "E:/Software/ELK/logstash-5.1.1/patterns/ingdevbw"  
pattern =\> "%^{BWTIME}"  
negate =\> true  
what =\> "previous"  
}  
}  
}

filter {  
grok {  
patterns\_dir =\> "E:/Software/ELK/logstash-5.1.1/patterns/ingdevbw"  
match =\> { "message" =\> "%{BWLOG}" }  
}  
date {  
match =\> ["timestamp" , "YYYY MMM DD HH:mm:ss:SSS"]  
remove\_field =\> ["timestamp"]  
}  
}  
output {  
if [type] == "esbbwlog" {  
elasticsearch {

 ![](https://us1.discourse-cdn.com/elastic/original/2X/1/1222133699154c8fb0dfb2a0a7263ce42035f19c.PNG) ![](https://us1.discourse-cdn.com/elastic/original/2X/f/f7803d332aed82f4fb241433426f7b7ba6cfe3d9.PNG) ![](https://us1.discourse-cdn.com/elastic/original/2X/d/dfff6ff9afcc1f7b27269cc422ea4a1894e3a225.PNG)  
hosts =\> ["IP:9200"]  
index =\> ["logstash-bw-devlog-%{+YYYY.MM.dd}"]  
}  
stdout { codec =\> rubydebug }  
}  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 9, 2017, 11:52am UTC](https://discuss.elastic.co/t/logstash-5-1-multiline-codec-with-file-input/70635/2 "2017-01-09T11:52:19Z")

</div>

> ```
> pattern => "%^{BWTIME}"
> 
> ```

You probably mean:

```
pattern => "^%{BWTIME}"

```

---

<div class="post-metadata">

**Author:** ![spravn789](https://avatars.discourse-cdn.com/v4/letter/s/e47c2d/32.png) [@spravn789](https://discuss.elastic.co/u/spravn789)\
**Post date:** [January 12, 2017, 4:28am UTC](https://discuss.elastic.co/t/logstash-5-1-multiline-codec-with-file-input/70635/3 "2017-01-12T04:28:28Z")

</div>

Yeah Magnus.

Sorry i meant pattern =\> "^%{BWTIME}".

Got the issue resolved. Thanks.  
Issue is because of below pattern as GMT +%{INT} is repeated twice.

BWTIME %{YEAR} %{MONTH} %{MONTHDAY} %{TIME} GMT +%{INT}  
BWLOG %{BWTIME:timestamp} GMT +%{INT} %{GREEDYDATA:Bwpayload}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 9, 2017, 4:28am UTC](https://discuss.elastic.co/t/logstash-5-1-multiline-codec-with-file-input/70635/4 "2017-02-09T04:28:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
