# Logstash multiline help

**URL:** <https://discuss.elastic.co/t/logstash-multiline-help/42852>\
**Category:** Logstash\
**Created:** [February 26, 2016, 1:30pm UTC](https://discuss.elastic.co/t/logstash-multiline-help/42852 "2016-02-26T13:30:37Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Roy\_K](https://avatars.discourse-cdn.com/v4/letter/r/90ced4/32.png) [@Roy\_K](https://discuss.elastic.co/u/Roy_K)\
**Post date:** [February 26, 2016, 1:30pm UTC](https://discuss.elastic.co/t/logstash-multiline-help/42852/1 "2016-02-26T13:30:37Z")

</div>

I am having an issue cobining this log into a multiline. Any suggestions on how I can use a specific timestamp is the identified to combine the line?

Log Example (notice the timestamp is the same):  
`[Thr 47613344799040] Trace dispatcher thread is successfully triggered [Thr 47613344799040] NCS data timer thread is successfully triggered [Thr 47613344799040] Data dispatcher thread is successfully triggered [Thr 47613344799040] Current NCS Configuration: [Thr 47613344799040] trace_enabled_via_e2e=1; [Thr 47613344799040] trace_enabled_via_em=0; [Thr 47613344799040] trace_preview_timeout=120; [Thr 47613344799040] tracecheck_interval=5; [Thr 47613344799040] tracesize_threshold=1000000; [Thr 47613344799040] zombie_check_interval=300; [Thr 47613344799040] zombie_timeout=86400; [Thr 47613344799040] NCS configuration info end----------------`

Is there any way to use match the timestamp to combine the line?

---

<div class="post-metadata">

**Author:** ![Justin\_V](https://avatars.discourse-cdn.com/v4/letter/j/fbc32d/32.png) [@Justin\_V](https://discuss.elastic.co/u/Justin_V)\
**Post date:** [February 26, 2016, 2:28pm UTC](https://discuss.elastic.co/t/logstash-multiline-help/42852/2 "2016-02-26T14:28:59Z")

</div>

You might have the same problem that I have : Combining the lines will not produce what you expect.  
[My post.](https://discuss.elastic.co/t/recover-only-a-part-of-a-log-with-multiline-codec/42824)  
I posted the question today, but I'm still trying to figure it by myself or waiting for a miracle 🙂  
By the way, you will easily find what you need to determine the pattern for the multiline codec on that page :  
[Github-grok patterns](https://github.com/elastic/logstash/blob/v1.4.2/patterns/grok-patterns)

---

<div class="post-metadata">

**Author:** ![Roy\_K](https://avatars.discourse-cdn.com/v4/letter/r/90ced4/32.png) [@Roy\_K](https://discuss.elastic.co/u/Roy_K)\
**Post date:** [February 26, 2016, 3:36pm UTC](https://discuss.elastic.co/t/logstash-multiline-help/42852/3 "2016-02-26T15:36:57Z")

</div>

Thanks ! Your issue is a bit different. I posted my solution to what I think you trouble is. For my issue, I want to combine lines based on timestamp x, rather than just matching the pattern. I guess it would be like matching anything in a log file with process id x, and make it multiline.

This may not be possible, but I wanted to ask the experts out there.

---

<div class="post-metadata">

**Author:** ![Justin\_V](https://avatars.discourse-cdn.com/v4/letter/j/fbc32d/32.png) [@Justin\_V](https://discuss.elastic.co/u/Justin_V)\
**Post date:** [February 26, 2016, 3:52pm UTC](https://discuss.elastic.co/t/logstash-multiline-help/42852/4 "2016-02-26T15:52:48Z")

</div>

If it's possible, it may help me too for my issue (the solution you proposed me just made the reverse effect : everything is linked to these particular logs =\> Because they are those who match the pattern. But thanks for the try ! )  
I keep an eye on your post, just in case 😉

---

<div class="post-metadata">

**Author:** ![Roy\_K](https://avatars.discourse-cdn.com/v4/letter/r/90ced4/32.png) [@Roy\_K](https://discuss.elastic.co/u/Roy_K)\
**Post date:** [February 26, 2016, 6:54pm UTC](https://discuss.elastic.co/t/logstash-multiline-help/42852/5 "2016-02-26T18:54:12Z")

</div>

I figured it out. I guess my original google search was too specific.

`grok { match => ["message", "\[%{WORD} %{NUMBER:TSID}\]" ] } multiline { stream_identity => "%{TSID}" pattern => "." # match anything because we're gathering by id field what => "previous" periodic_flush => true max_age => 10 # however many seconds it takes to get all of your lines together }`

This results in the log above being combined into a multiline.

Found here:  
`http://stackoverflow.com/questions/32304023/how-to-make-logstash-multiline-filter-merge-lines-based-on-some-dynamic-field-va`

---

<div class="post-metadata">

**Author:** ![Justin\_V](https://avatars.discourse-cdn.com/v4/letter/j/fbc32d/32.png) [@Justin\_V](https://discuss.elastic.co/u/Justin_V)\
**Post date:** [February 29, 2016, 7:46am UTC](https://discuss.elastic.co/t/logstash-multiline-help/42852/6 "2016-02-29T07:46:42Z")

</div>

That's nice : but multiline filter is deprecated... And "stream\_identity" doesn't exist in multiline codec 😕  
I search for the equivalent, and I warn you if I find anything

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:09am UTC](https://discuss.elastic.co/t/logstash-multiline-help/42852/7 "2017-07-06T05:09:25Z")

</div>


