# Logstash grok pattern issue

**URL:** <https://discuss.elastic.co/t/logstash-grok-pattern-issue/198950>\
**Category:** Logstash\
**Created:** [September 10, 2019, 5:48pm UTC](https://discuss.elastic.co/t/logstash-grok-pattern-issue/198950 "2019-09-10T17:48:45Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![mugil1988](https://avatars.discourse-cdn.com/v4/letter/m/f14d63/32.png) [@mugil1988](https://discuss.elastic.co/u/mugil1988)\
**Post date:** [September 10, 2019, 5:48pm UTC](https://discuss.elastic.co/t/logstash-grok-pattern-issue/198950/1 "2019-09-10T17:48:45Z")

</div>

Hi All,

I am trying to configure grok patter to parse my application logs.

Part of the logs is not getting displayed in kibana.

**Sample logs :**

2019-09-10T23:04:21,584 | INFO | ://dedupresquest | \_route1 | ID-ESB-Dev--in-1567014689815-54-2532 | {"txnid":"SME-LOS20180912122512345","source":"SME-LOS","timestamp":"10-2019-09 17-50-21","Type":"Source Response","Payload":{  
"status" : "Success",  
"message" : "Created Successfully"  
},"status":"success"}

**Grok Pattern :**

```
(?m)%{TIMESTAMP_ISO8601:timestamp}%{SPACE}\|%{SPACE}%{WORD:LogLevel}%{SPACE}\|%{SPACE}%{GREEDYDATA:Word} \|%{SPACE}%{WORD:Routename}%{SPACE}\|%{SPACE}%{GREEDYDATA:ID}%{SPACE}\|(?m)%{GREEDYDATA:payload}"

```

**Kibana Display logs :**

{"txnid":"SME-LOS20180912122512345","source":"SME-LOS","timestamp":"10-2019-09 17-50-21","Type":"Source Response","Payload":{

Kindly help!!!

Regards,  
Mugil

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 10, 2019, 7:01pm UTC](https://discuss.elastic.co/t/logstash-grok-pattern-issue/198950/2 "2019-09-10T19:01:03Z")

</div>

If the log message is really spread across four lines you will need a multiline codec to join them back together before you grok them. You may be able to use a regexp that [matches the timestamp](https://discuss.elastic.co/t/guidance-for-parsing-log-file/165604/2) to do that.

---

<div class="post-metadata">

**Author:** ![mugil1988](https://avatars.discourse-cdn.com/v4/letter/m/f14d63/32.png) [@mugil1988](https://discuss.elastic.co/u/mugil1988)\
**Post date:** [September 11, 2019, 5:45am UTC](https://discuss.elastic.co/t/logstash-grok-pattern-issue/198950/3 "2019-09-11T05:45:24Z")

</div>

Thanks for the reply.

I am using filebeat to harvest logs.

I am using multiline pattern & negate options in filebeat config.

**Filebeat config**

multiline.pattern: '^%{TIMESTAMP\_ISO8601}'  
multiline.negate: false  
multiline.match: after

Still facing same issue.

Do i need to change anything in filebeat config?

Regards,  
Mugil

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 9, 2019, 5:45am UTC](https://discuss.elastic.co/t/logstash-grok-pattern-issue/198950/4 "2019-10-09T05:45:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
