# Logstash multiline codec not working with my pattern

**URL:** <https://discuss.elastic.co/t/logstash-multiline-codec-not-working-with-my-pattern/30085>\
**Category:** Logstash\
**Created:** [September 27, 2015, 2:07pm UTC](https://discuss.elastic.co/t/logstash-multiline-codec-not-working-with-my-pattern/30085 "2015-09-27T14:07:07Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jigar\_Sheth](https://avatars.discourse-cdn.com/v4/letter/j/e274bd/32.png) [@Jigar\_Sheth](https://discuss.elastic.co/u/Jigar_Sheth)\
**Post date:** [September 27, 2015, 2:07pm UTC](https://discuss.elastic.co/t/logstash-multiline-codec-not-working-with-my-pattern/30085/1 "2015-09-27T14:07:07Z")

</div>

I had been using the multline codec of logstash for my java  
exceptions. However, recently I wanted to capture more things and hence  
used another pattern. This causes my logstash not to read file even  
though I am using sincedb\_path attribute.

My configurations file -

```
input {
        file {
           type => "pa"
           path => "/home/jigar/POC/Docs/smalllogs/test"
           codec => multiline {
                pattern => "^%{DATESTAMP}"
                negate => true
                what => "previous"
           }
           start_position => "beginning"
           sincedb_path => "/dev/null"
        }
}

filter {
         grok {
           match => ["message", "%{DATESTAMP:actualTimeStamp}%{SPACE}%{LOGLEVEL:level}%{SPACE}%{GREEDYDATA:identifier}%{SYSLOG5424SD:Id}%{SPACE}%{JAVACLASS:package}:%{INT:lineNum}%{SPACE}-%{SPACE}%{DATA:mydata}\n(\t)?%{GREEDYDATA:stack}"]
         }
}

output {
  elasticsearch {
        cluster => "smartdebugger"
        protocol => "http"
        host => "localhost"
  }
  stdout { codec =>rubydebug }
}

```

Can somebody please help me why logstash is not able to read the file.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 27, 2015, 6:39pm UTC](https://discuss.elastic.co/t/logstash-multiline-codec-not-working-with-my-pattern/30085/2 "2015-09-27T18:39:00Z")

</div>

I can imagine a couple of explanations:

- Logstash can't read /home/jigar/POC/Docs/smalllogs/test.
- The multiline pattern never matches, so Logstash waits forever for a matching line so that it can emit a message.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:27am UTC](https://discuss.elastic.co/t/logstash-multiline-codec-not-working-with-my-pattern/30085/3 "2017-07-06T05:27:54Z")

</div>


