# Logstash: Configuration for websphere

**URL:** https://discuss.elastic.co/t/logstash-configuration-for-websphere/44295
**Category:** Logstash
**Created:** [March 14, 2016, 8:49am UTC](https://discuss.elastic.co/t/logstash-configuration-for-websphere/44295 "2016-03-14T08:49:55Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![krushnat\_khawale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/krushnat_khawale/32/6652_2.png) [@krushnat\_khawale](https://discuss.elastic.co/u/krushnat_khawale)
#### Post date: [March 14, 2016, 8:49am UTC](https://discuss.elastic.co/t/logstash-configuration-for-websphere/44295/1 "2016-03-14T08:49:55Z")

</div>

Following is my configuration file for logstash to read data from websphere logs.

```
input { 
      file {
        type => "bolbo"
        path => ["D:/Users/abced/Documents/My Received Files/1003/1003/gca1.log"]
        start_position => "beginning"
    }
}
filter {        
          
}
output {  
    elasticsearch {
        hosts => "localhost:9200"
        index => "webspherelogs"
    }
    stdout { }
}

```

**My Log file data is as follows,**

```
2016-03-11 06:36:48,845 [WebSphere_EJB_Timer_Service_WorkManager.Alarm Pool : 0] ERROR com.lord.mss.cddb.gca.service.export.ExportConsumerServiceImpl - 'Could not export changed entities, exportId: 424572'
com.lord.mss.cddb.gca.persistence.dao.DaoException: Io exception: Socket read timed out
	at com.lord.mss.cddb.gca.persistence.cdb.export.IdToExportFinder.getIdsToExport(IdToExportFinder.java:107)

```

It is reading the data and showing 4 rows for example, and also consist of only one column **message**

My question is,  
1) How do I specify column names for my data here?  
2) As data is multiline, how it can be configured to treat a new document which starts with date in above format?

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [March 14, 2016, 8:54am UTC](https://discuss.elastic.co/t/logstash-configuration-for-websphere/44295/2 "2016-03-14T08:54:38Z")

</div>

1. Use a grok filter.
2. Use a multiline codec for your file input that treats lines that _don't_ begin with a timestamp as belonging to the preceding line.

How to parse Java logs comes up here (and on other places like StackOverflow) rather frequently so you should be able to find something that's at least very close to what you need.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 6, 2017, 5:07am UTC](https://discuss.elastic.co/t/logstash-configuration-for-websphere/44295/3 "2017-07-06T05:07:11Z")

</div>


