# Logstash multiline codec plugin

**URL:** <https://discuss.elastic.co/t/logstash-multiline-codec-plugin/136236>\
**Category:** Logstash\
**Created:** [June 18, 2018, 4:21am UTC](https://discuss.elastic.co/t/logstash-multiline-codec-plugin/136236 "2018-06-18T04:21:16Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![bobbytan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bobbytan/32/32720_2.png) [@bobbytan](https://discuss.elastic.co/u/bobbytan)\
**Post date:** [June 18, 2018, 4:21am UTC](https://discuss.elastic.co/t/logstash-multiline-codec-plugin/136236/1 "2018-06-18T04:21:16Z")

</div>

hello,

Im trying to use the multiline codec plugin to merge input log that contains several lines into one line within a textfile.

**config file:**  
input {

file {  
path =\> "C:\Users\bob\Downloads\data\error\_test.txt"  
start\_position =\>"beginning"  
codec =\> multiline {  
pattern =\> "^%{TIMESTAMP\_ISO8601} "  
negate =\> true  
what =\> "previous"

}  
}  
}

filter {  
grok{  
match =\> ["message", "%{TIMESTAMP\_ISO8601:logdate} %{LOGLEVEL:loglevel} %{GREEDYDATA:messsage}"]  
}  
date {  
match =\> ["logdate", "yyyy-MM-dd HH:mm:ss,SSS", "ISO8601"]  
}

}

output{  
stdout { codec =\> rubydebug }  
elasticsearch { hosts =\> ["localhost:9200"]  
index=\> "error\_test"  
}  
stdout { codec =\> rubydebug }  
}

After running config file in shell it shows that pipelines are running and no errors are shown.However stdout are not printed within the shell running Logstash and no results are found for the particular index on kibana.Please advice thanks.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 18, 2018, 6:32am UTC](https://discuss.elastic.co/t/logstash-multiline-codec-plugin/136236/2 "2018-06-18T06:32:18Z")

</div>

Perhaps Logstash thinks it has already processed the file and is waiting for more input. Setting `sincedb_path => "nul"` in the file input will clear that.

---

<div class="post-metadata">

**Author:** ![bobbytan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bobbytan/32/32720_2.png) [@bobbytan](https://discuss.elastic.co/u/bobbytan)\
**Post date:** [June 18, 2018, 6:46am UTC](https://discuss.elastic.co/t/logstash-multiline-codec-plugin/136236/3 "2018-06-18T06:46:52Z")

</div>

thanks for the feedback.I have tried setting in file input **_sincedb\_path =\> "nul"_** and also **_sincedb\_path =\> "/dev/null"_** however the same issue still persists

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 18, 2018, 7:10am UTC](https://discuss.elastic.co/t/logstash-multiline-codec-plugin/136236/4 "2018-06-18T07:10:40Z")

</div>

Things to try:

- Remove the multiline codec.
- Use forward slashes instead of backslashes in the path to the logfile.
- Increase Logstash's loglevel and search for "error\_test.txt" in the Logstash log.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 16, 2018, 7:10am UTC](https://discuss.elastic.co/t/logstash-multiline-codec-plugin/136236/5 "2018-07-16T07:10:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
