# Logstash multiline codec plugin won't keep blank lines

**URL:** <https://discuss.elastic.co/t/logstash-multiline-codec-plugin-wont-keep-blank-lines/293429>\
**Category:** Logstash\
**Created:** [January 4, 2022, 10:31am UTC](https://discuss.elastic.co/t/logstash-multiline-codec-plugin-wont-keep-blank-lines/293429 "2022-01-04T10:31:12Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![saprof](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/saprof/32/99799_2.png) [@saprof](https://discuss.elastic.co/u/saprof)\
**Post date:** [January 4, 2022, 10:31am UTC](https://discuss.elastic.co/t/logstash-multiline-codec-plugin-wont-keep-blank-lines/293429/1 "2022-01-04T10:31:12Z")

</div>

Hi,

I am working on the correct settings for the multiline codec plugin. I want to join all lines between two `\r\n` into a single event and it works well, except that blank lines are dropped.

I'm running Logstash v7.16.1 with the following debug setup:

Logstash config:

```auto
input {
    file {
        path => "${SKY_IMPORT_PATH}"
        file_completed_action => "log"
        file_completed_log_path => "/dev/null"
        mode => "read"
        exit_after_read => true
        file_chunk_size => 100000000000
        sincedb_path => "/dev/null"
        codec => multiline {
            pattern => "\r$"
            negate => true
            what => "next"
        }
    }
 }

output {  
  stdout {}
}

```

Test file:

```auto
header\r\n
line1:a\n
b\n
\n
c\n
d\r\n

```

If I run logstash with multiline codec disabled, it outputs each line as a separate event, as expected, i.e. separate events with the messages `header\r`, `line1:a`, `b`, `<empty string>`, `c`, `d\r` respectively. Note that the blank line is not dropped.

If I run logstash with the multiline codec enabled, it joins the lines as intended except for dropping the blank line.  
I get two events with messages `header\r` and `line1:a\nb\nc\nd\r` but I would expect (and need) the second message to be `line1:a\nb\n\nc\nd\r`, i.e. containing the blank line from the test file.  
Also, If I add more line breaks into my test file, every group of consecutive `\n` is collapsed into a single `\n`.

Can somebody help me saving my blank line, please? 🙂

Thanks,  
Samuel

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 4, 2022, 4:56pm UTC](https://discuss.elastic.co/t/logstash-multiline-codec-plugin-wont-keep-blank-lines/293429/2 "2022-01-04T16:56:10Z")

</div>

> [@saprof](#):
>
> Can somebody help me saving my blank line, please?

A multiline codec drops blank lines. See Guy's comments on [this](https://github.com/logstash-plugins/logstash-input-file/issues/118) issue and [this](https://discuss.elastic.co/t/multiline-codec-discrepancies-between-file-and-stdin-inputs/47686/7) post in the forum.

---

<div class="post-metadata">

**Author:** ![saprof](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/saprof/32/99799_2.png) [@saprof](https://discuss.elastic.co/u/saprof)\
**Post date:** [January 4, 2022, 7:26pm UTC](https://discuss.elastic.co/t/logstash-multiline-codec-plugin-wont-keep-blank-lines/293429/3 "2022-01-04T19:26:57Z")

</div>

Thanks for the quick response.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 1, 2022, 7:27pm UTC](https://discuss.elastic.co/t/logstash-multiline-codec-plugin-wont-keep-blank-lines/293429/4 "2022-02-01T19:27:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
