# Logstash failing to ingest multi-line json log file... I think

**URL:** <https://discuss.elastic.co/t/logstash-failing-to-ingest-multi-line-json-log-file-i-think/291851>\
**Category:** Elasticsearch\
**Created:** [December 14, 2021, 5:52pm UTC](https://discuss.elastic.co/t/logstash-failing-to-ingest-multi-line-json-log-file-i-think/291851 "2021-12-14T17:52:07Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![4art4](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/4art4/32/98919_2.png) [@4art4](https://discuss.elastic.co/u/4art4)\
**Post date:** [December 16, 2021, 9:56pm UTC](https://discuss.elastic.co/t/logstash-failing-to-ingest-multi-line-json-log-file-i-think/291851/2 "2021-12-16T21:56:05Z")

</div>

OK. I was able to figure out several things:

First, I am having two problems. That makes learning a new thing rather difficult. The default behavior of _logstash_ it to treat each line as a separate entry. And... This part of the json is not parsing:

```auto
  "metrics": [
    {
      "MetricName": "ResourceCount",
      "Timestamp": "2021-12-06T11:29:48.934903",
      "Value": 0,
      "Unit": "Count"
    },
    {
      "MetricName": "ResourceTime",
      "Timestamp": "2021-12-06T11:29:48.934920",
      "Value": 0.8265008926391602,
      "Unit": "Seconds"
    }
  ]

```

I was able to solve the mutilline thing with the help of this page: [Parsing array of json objects with logstash and injesting to elastic](https://discuss.elastic.co/t/parsing-array-of-json-objects-with-logstash-and-injesting-to-elastic/203197)

I changed my input to:

```auto
file {
            start_position => "beginning"
            path => "/etc/logstash/sample/cctest1.log"
            sincedb_path => "/dev/null"
            codec => multiline {
                pattern => "^({|\[)\s*$"
                negate => true
                auto_flush_interval => 1
                multiline_tag => ""
                what => "previous"
            }
}

```

So a line that only contains a "{" or a "[" with possible white space after will trigger a new entry.

So it still will not parse the json. I figure I need to do a "split", but I am not understanding that well enough I guess.

The problem looks alot like the the one I referenced above. But "split { field =\> "someField" }" makes no sense to me.

---

_[View the full topic](https://discuss.elastic.co/t/logstash-failing-to-ingest-multi-line-json-log-file-i-think/291851)._
