# Logstash grok pattern issue

**URL:** <https://discuss.elastic.co/t/logstash-grok-pattern-issue/198950>\
**Category:** Logstash\
**Created:** [September 10, 2019, 5:48pm UTC](https://discuss.elastic.co/t/logstash-grok-pattern-issue/198950 "2019-09-10T17:48:45Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 10, 2019, 7:01pm UTC](https://discuss.elastic.co/t/logstash-grok-pattern-issue/198950/2 "2019-09-10T19:01:03Z")

</div>

If the log message is really spread across four lines you will need a multiline codec to join them back together before you grok them. You may be able to use a regexp that [matches the timestamp](https://discuss.elastic.co/t/guidance-for-parsing-log-file/165604/2) to do that.

---

_[View the full topic](https://discuss.elastic.co/t/logstash-grok-pattern-issue/198950)._
