# Logstash Multiline Parse Error

**URL:** <https://discuss.elastic.co/t/logstash-multiline-parse-error/126051>\
**Category:** Logstash\
**Created:** [March 29, 2018, 8:45am UTC](https://discuss.elastic.co/t/logstash-multiline-parse-error/126051 "2018-03-29T08:45:13Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![rahulnama](https://avatars.discourse-cdn.com/v4/letter/r/8c91f0/32.png) [@rahulnama](https://discuss.elastic.co/u/rahulnama)\
**Post date:** [March 29, 2018, 8:45am UTC](https://discuss.elastic.co/t/logstash-multiline-parse-error/126051/1 "2018-03-29T08:45:14Z")

</div>

Hello,

My log file has multiline patterns(it's a CSV file having around 15 fields)

example log:

IM25756756,ADDRESS SERVICE (HPI),01/05/2018 15:41:12,67,mlm,202227,Closed,[c1t09878.itcs.hpicorp.net](http://c1t09878.itcs.hpicorp.net),W-INCFLS-HPIT-LINUX,W-INCFLS-HPIT-LINUX,W-INCFLS-HPIT-LINUX,01/11/2018 15:41:11,4,incident,01/05/2018 15:41:15,2018/01,javier.de-la-torre@hpe.com,Mission Critical,HPOO,Failed to contact node [c1t09878.itcs.hpicorp.net](http://c1t09878.itcs.hpicorp.net) with BBC. Probably the node is down or there's a network problem. (OpC40-1911),"Failed to contact node [c1t09878.itcs.hpicorp.net](http://c1t09878.itcs.hpicorp.net) with BBC. Probably the node is down or  
there's a network problem. (OpC40-1911)",1,1

Log always start with IM, moreover, **If i align the log in single line its working** but I can't do that for thousands of logs

So I'm using multiline pattern

codec =\> multiline {  
pattern =\> "^(?!IM)\w+$"  
what =\> "previous"  
}  
Lines not starting with IM should merge with previous line. Still it's not working.

Error is: #\<CSV::MalformedCSVError: Unclosed quoted field on line 1.\>  
Please Let me know where I am wrong.  
Thanks for your valuable time

---

<div class="post-metadata">

**Author:** ![Dvikas](https://avatars.discourse-cdn.com/v4/letter/d/a9adbd/32.png) [@Dvikas](https://discuss.elastic.co/u/Dvikas)\
**Post date:** [March 29, 2018, 12:40pm UTC](https://discuss.elastic.co/t/logstash-multiline-parse-error/126051/2 "2018-03-29T12:40:05Z")

</div>

Check multiline option in filebeat and give your multiline.pattern: '^(?!IM)\w+$' (Is this the start of the line?) and do multiline.negate: true

---

<div class="post-metadata">

**Author:** ![rahulnama](https://avatars.discourse-cdn.com/v4/letter/r/8c91f0/32.png) [@rahulnama](https://discuss.elastic.co/u/rahulnama)\
**Post date:** [March 30, 2018, 1:26am UTC](https://discuss.elastic.co/t/logstash-multiline-parse-error/126051/3 "2018-03-30T01:26:17Z")

</div>

Every line starts with IM. so In regex, I have given Lines not starting with IM(!IM). So, I think no need to use multiline.negate. I'm not using Filebeat as of now.

Anyway this worked finally

codec =\> multiline {  
pattern =\> "(^IM\*)"  
negate =\> true  
what =\> "previous"  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 27, 2018, 1:26am UTC](https://discuss.elastic.co/t/logstash-multiline-parse-error/126051/4 "2018-04-27T01:26:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
