# Logstash input multiline codec Entire file is getting merged into single line

**URL:** <https://discuss.elastic.co/t/logstash-input-multiline-codec-entire-file-is-getting-merged-into-single-line/226453>\
**Category:** Logstash\
**Created:** [April 3, 2020, 6:14pm UTC](https://discuss.elastic.co/t/logstash-input-multiline-codec-entire-file-is-getting-merged-into-single-line/226453 "2020-04-03T18:14:00Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![ranjith](https://avatars.discourse-cdn.com/v4/letter/r/8797f3/32.png) [@ranjith](https://discuss.elastic.co/u/ranjith)\
**Post date:** [April 3, 2020, 6:14pm UTC](https://discuss.elastic.co/t/logstash-input-multiline-codec-entire-file-is-getting-merged-into-single-line/226453/1 "2020-04-03T18:14:00Z")

</div>

Hi All,

I am creating a logstash pipeline to process the following logs

 ![log](https://us1.discourse-cdn.com/elastic/original/3X/3/7/372ba44dfb024eade6950e5d5632587a6eb709f5.jpeg)

My logstash config is

> input{  
> file{  
> path =\> "E:/Grok\_Practice/Practice/e.log"  
> start\_position =\> "beginning"  
> sincedb\_path =\> "LOG\_NULL"  
> codec =\> multiline {  
> pattern =\> "^\d"  
> negate =\> true  
> what =\> "previous"  
> auto\_flush\_interval =\> 1  
> }  
> }  
> }

The output is the entire log lines are getting merged into a single line as follows

> "tags" =\> [  
> [0] "multiline"  
> ],  
> "message" =\> "12546\tMon Mar 30 08:02:36.902032\tipcmisc.c355\r\tIPC1300002 - INFO: JDEIPC Initialized semaphore array: key=8002, numSems=1000, id=27\r\r12546\tMon Mar 30 08:02:36.932640\tipcmisc.c355\r\tprocess 12546 \<E910SYS/JDENET\_K\> registered in entry 60\r\r12546\tMon Mar 30 08:02:36.974264\tnetcfg.c297\r\tStarting Kernel of Type:CALL OBJECT KERNEL\r\r12546\tMon Mar 30 08:02:37.905752\txmlrequest.cpp1335\r\tICU0000017 - ICU CodePage for 37 is ibm-37.\r\r12546\tMon Mar 30 08:02:37.911968\tjdekdisp.c2735\r\tINITIALIZING CALL OBJECT KERNEL\r\r12546\tMon Mar 30 08:02:37.917520\twinansi.c1420\r\tLIB0000572 - WARNING!!! [SECURITY][Password] Password not encrypted in the INI\r\r12546\tMon Mar 30 08:02:37.932992\twinansi.c1420\r\tLIB0000572 - WARNING!!! [SECURITY][Password] Password not encrypted in the INI\r\r12546\tMon Mar 30 08:02:38.276624\twinansi.c1420\r\tLIB0000572 - WARNING!!! [SECURITY][Password] Password not encrypted in the INI\r\r12546\tMon Mar 30 08:02:38.278176\tjdekdisp.c2824\r\tKNT0000888 - Call Object Kernel Thread Pool in multi-threaded mode.\r\r12546\tMon Mar 30 08:02:38.278240\tjdekdisp.c2831\r\tKNT0000999 - Call Object Kernel Thread Pool Setting: size 20, increment 5\r\r"

I am stuck on this. This works for me if I copy the contents of the inputs file at that time end of line character is **LF**. But directly copying the file from the AS 400 server it is not working because the end of character is **CR**.

Is there anyway to handle this?

Any suggestions for the above would be more helpful for me.

Thanks in advance,  
Ranjith

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 3, 2020, 8:40pm UTC](https://discuss.elastic.co/t/logstash-input-multiline-codec-entire-file-is-getting-merged-into-single-line/226453/2 "2020-04-03T20:40:55Z")

</div>

You could use the delimiter option on the file input to tell it what line endings are in the file.

If you are running on Windows and do not want the file input to persist the in-memory sincedb across restarts then set 'sincedb\_path =\> "NUL"'.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 1, 2020, 8:41pm UTC](https://discuss.elastic.co/t/logstash-input-multiline-codec-entire-file-is-getting-merged-into-single-line/226453/3 "2020-05-01T20:41:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
