# Logstash multiline pattern

**URL:** <https://discuss.elastic.co/t/logstash-multiline-pattern/88564>\
**Category:** Logstash\
**Created:** [June 7, 2017, 11:29am UTC](https://discuss.elastic.co/t/logstash-multiline-pattern/88564 "2017-06-07T11:29:15Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![deeps123](https://avatars.discourse-cdn.com/v4/letter/d/90db22/32.png) [@deeps123](https://discuss.elastic.co/u/deeps123)\
**Post date:** [June 7, 2017, 11:29am UTC](https://discuss.elastic.co/t/logstash-multiline-pattern/88564/1 "2017-06-07T11:29:15Z")

</div>

Hi,

How to write pattern inside multiline codec to append the data till nth occurrence of the string.

Like eg-  
File content is this:  
public class Constr1 { private int a; public Constr1 () { Constr1 Constr1 Constr1 //super(); a = 1; //super(); } }

regex- (?:._?(Constr1)+){3}._?((Constr1)+)

Result - [https://regex101.com/r/nM6qN0/1](https://regex101.com/r/nM6qN0/1)  
Above pattern is working fine in online regular expression but while using in logstash its not working. My config file looks below:

input {  
file {  
path =\> "Data.log"  
start\_position =\> beginning  
sincedb\_path=\>"/dev/null"  
codec =\> multiline {  
pattern =\>"(?:.\*?(Constr1)+){3}"  
negate =\>"false"  
what =\>"previous"  
}  
}  
}

output {

file {  
codec =\> line {  
format =\> "%{[time]} - %{[message]}"  
}  
path =\> "/Users/dnataraj1/Desktop/Goreply\_preprod\_logs/test/reqresp-%{+YYYY-MM-dd}123.log"  
}  
}

Please help.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:29am UTC](https://discuss.elastic.co/t/logstash-multiline-pattern/88564/2 "2017-07-05T11:29:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
