# Logstash cannot read new lines that are coming from .NET error exception msg

**URL:** <https://discuss.elastic.co/t/logstash-cannot-read-new-lines-that-are-coming-from-net-error-exception-msg/351340>\
**Category:** Logstash\
**Created:** [January 18, 2024, 9:32am UTC](https://discuss.elastic.co/t/logstash-cannot-read-new-lines-that-are-coming-from-net-error-exception-msg/351340 "2024-01-18T09:32:31Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![theo003](https://avatars.discourse-cdn.com/v4/letter/t/8e7dd6/32.png) [@theo003](https://discuss.elastic.co/u/theo003)\
**Post date:** [January 18, 2024, 9:32am UTC](https://discuss.elastic.co/t/logstash-cannot-read-new-lines-that-are-coming-from-net-error-exception-msg/351340/1 "2024-01-18T09:32:31Z")

</div>

Hello,

Our system is throwing some error exceptions in the logs with the following format:

```auto
|17 01 2024 08:22:10,614| |ERROR| CreateSession API... File: "File_name" Line: 290System.InvalidOperationException: "Error_msg"
   at "Location" in "File":line 243
   at "Location" in "File":line 290

```

Logstash read only the first line of the log message. In the logstash.conf we tried to mutate the logmsg but still not working. Your assistance will be much appreciated.

```auto
filter {
  dissect {
    mapping => {
        "message" => "|%{time}| |%{level}| %{logmsg}"
      }
}
  kv {
    field_split => " "
}
  mutate {
    remove_field => ["event","input","ecs","version","name","@version","input","type","agent","offset","tags"]
    lowercase => ["[host][name]" ]
    lowercase => ["[level]" ]
    lowercase => ["[Application_Name]" ]
    gsub => ["logmsg", "[\r\n]+", "line"]
    gsub => ["logmsg", "[\r]+", "line"]
    gsub => ["logmsg", "[\n]+", "line"]
}
}
  output {
      stdout {codec => rubydebug }
      elasticsearch {...}
}

```

---

<div class="post-metadata">

**Author:** ![yago82](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yago82/32/97755_2.png) [@yago82](https://discuss.elastic.co/u/yago82)\
**Post date:** [January 18, 2024, 11:34am UTC](https://discuss.elastic.co/t/logstash-cannot-read-new-lines-that-are-coming-from-net-error-exception-msg/351340/2 "2024-01-18T11:34:13Z")

</div>

> [@theo003](#):
>
> Hello,
> 
> Our system is throwing some error exceptions in the logs with the following format:
> 
> ```auto
> |17 01 2024 08:22:10,614| |ERROR| CreateSession API... File: "File_name" Line: 290System.InvalidOperationException: "Error_msg"
> at "Location" in "File":line 243
> at "Location" in "File":line 290
> 
> ```
> 
> Logstash read only the first line of the log message. In the logstash.conf we tried to mutate the logmsg but still not working. Your assistance will be much appreciated.
> 
> ```auto
> filter {
> dissect {
> mapping => {
> "message" => "|%{time}| |%{level}| %{logmsg}"
> }
> }
> kv {
> field_split => " "
> }
> mutate {
> remove_field => ["event","input","ecs","version","name","@version","input","type","agent","offset","tags"]
> lowercase => ["[host][name]" ]
> lowercase => ["[level]" ]
> lowercase => ["[Application_Name]" ]
> gsub => ["logmsg", "[\r\n]+", "line"]
> gsub => ["logmsg", "[\r]+", "line"]
> gsub => ["logmsg", "[\n]+", "line"]
> }
> }
> output {
> stdout {codec => rubydebug }
> elasticsearch {...}
> }
> 
> ```

Hi,

i think that the issue you're experiencing is likely due to multiline log messages.

> **[Multiline codec plugin | Logstash Reference \[8.12\] | Elastic](https://www.elastic.co/guide/en/logstash/current/plugins-codecs-multiline.html)**

Regards

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [January 18, 2024, 12:26pm UTC](https://discuss.elastic.co/t/logstash-cannot-read-new-lines-that-are-coming-from-net-error-exception-msg/351340/3 "2024-01-18T12:26:54Z")

</div>

What is your input? You didn't share.

You have multiline logs, so you need to configure this in your input, if you are reading the files directly with Logstash, then you need to configure in the file input, if you are using beats to send the logs, then the multiline needs to be configured in beats, not logstash.

---

<div class="post-metadata">

**Author:** ![theo003](https://avatars.discourse-cdn.com/v4/letter/t/8e7dd6/32.png) [@theo003](https://discuss.elastic.co/u/theo003)\
**Post date:** [January 19, 2024, 8:33am UTC](https://discuss.elastic.co/t/logstash-cannot-read-new-lines-that-are-coming-from-net-error-exception-msg/351340/4 "2024-01-19T08:33:55Z")

</div>

Hello,

Thank you for your help! We manage to sort this out with multiline in the filebeat .yml file configuration because we are using beats as input.

We used the following link for guide:

> **[Manage multiline messages | Filebeat Reference \[8.12\] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/multiline-examples.html)**

I will also share my multiline configuration for reference:  
filebeat.yml:

```auto
filebeat.inputs:
- type: log
  paths:
    C:\...
  multiline.type: pattern
  multiline.pattern: '^\|'
  multiline.negate: true
  multiline.match: after

```

logstash.conf:

```auto
input {
  beats {
    port => 5050
  }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 16, 2024, 8:34am UTC](https://discuss.elastic.co/t/logstash-cannot-read-new-lines-that-are-coming-from-net-error-exception-msg/351340/5 "2024-02-16T08:34:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
