# Logstash grok multiple pattern , multi-line

**URL:** <https://discuss.elastic.co/t/logstash-grok-multiple-pattern-multi-line/264860>\
**Category:** Logstash\
**Created:** [February 19, 2021, 1:18pm UTC](https://discuss.elastic.co/t/logstash-grok-multiple-pattern-multi-line/264860 "2021-02-19T13:18:47Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Daniel\_Jankech](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/daniel_jankech/32/77691_2.png) [@Daniel\_Jankech](https://discuss.elastic.co/u/Daniel_Jankech)\
**Post date:** [February 19, 2021, 1:18pm UTC](https://discuss.elastic.co/t/logstash-grok-multiple-pattern-multi-line/264860/1 "2021-02-19T13:18:47Z")

</div>

Hello everyone , Im using grok to parse log file consisting of multiple pattern lines , these multiple lines represent one task being done in the system. My question is how should I do this if I need to add fields to the output field with each new line being read and matched to different pattern. If so could I make completely new field after matching last line of task and so getting multiple output fields for one big log file containing multiple tasks ?

Unfortunately cant fit in the whole log lines but in the beginning there is the same pattern in each and every line , I'm doing different patters to match some fields from greedydata after [5fda1d109ceec746643760f5]

```
2020-12-16 15:43:33.035 INFO 18020 --- [http-nio-8080-exec-7] c.n.w.workflow.service.TaskService : [5fda1d109ceec746643760f5]: Task [GENERATE] in case [11.11.2020 13:20] assigned to [super@netgrif.com]
2020-12-16 15:43:33.012 INFO 18020 --- [http-nio-8080-exec-7] c.n.w.workflow.service.TaskService : [5fda1d109ceec746643760f5]: Task [GENERATE] in case [11.11.2020 13:20] evaluating rules of event ASSIGN of phase POST
2020-12-16 15:43:33.009 INFO 18020 --- [http-nio-8080-exec-7] c.n.w.workflow.service.DataService : [5fda1d109ceec746643760f5]: Running actions of transition 12

```

EDIT: deleted image , added log sample into code formatter

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [February 19, 2021, 1:30pm UTC](https://discuss.elastic.co/t/logstash-grok-multiple-pattern-multi-line/264860/2 "2021-02-19T13:30:01Z")

</div>

Please, do not share images, sometimes it is hard to read and it is impossible to replicate anything.

Share a sample of your log as a text, using the code formatter the `<\>`button.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 19, 2021, 1:30pm UTC](https://discuss.elastic.co/t/logstash-grok-multiple-pattern-multi-line/264860/3 "2021-03-19T13:30:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
