# Logstash - Parsing Log Messages

**URL:** <https://discuss.elastic.co/t/logstash-parsing-log-messages/132630>\
**Category:** Logstash\
**Created:** [May 21, 2018, 8:37am UTC](https://discuss.elastic.co/t/logstash-parsing-log-messages/132630 "2018-05-21T08:37:11Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sunillinus](https://avatars.discourse-cdn.com/v4/letter/s/2bfe46/32.png) [@Sunillinus](https://discuss.elastic.co/u/Sunillinus)\
**Post date:** [May 21, 2018, 8:37am UTC](https://discuss.elastic.co/t/logstash-parsing-log-messages/132630/1 "2018-05-21T08:37:11Z")

</div>

Hi,

I have a log file which contains a timestamp and logs message as shown below:  
I need one multiple pattern such that if the line does not start with the timestamp it should be joined with the preceding line. Can anyone post me how input plugin should be written for this scenario.

Here is my log message:

10-05-2018 00:00:00.0031 DEBUG Thd: 6540 [Schedule] (checkSchedules) Chequea a: 10/05/2018 12:00:00 AM ON 10/05/2018 12:00:00 AM  
10-05-2018 00:00:00.0031 DEBUG Thd: 6540 [Schedule] (checkSchedules) ThreadFinished: 00:00:00  
10-05-2018 00:00:01.1904 ERROR Thd: 6568 192.168.56.1 [ManagedObject] (EntityLoad) Object not be loaded 192.168.56.1 AGENT  
Adecef.TelgatNGOSS.ObjectServer.ManagedObjectException: instance does not exists  
at Adecef.TelgatNGOSS.ObjectServer.ManagedObject.EntityLoad()  
10-05-2018 00:00:01.1904 ERROR Thd: 6568 [ObjectServer] (GetManagedObject) Object can not be load: 192.168.56.1  
Adecef.TelgatNGOSS.ObjectServer.ManagedObjectException: instance does not exists  
at Adecef.TelgatNGOSS.ObjectServer.ManagedObject.EntityLoad()  
at Adecef.TelgatNGOSS.ObjectServer.MAgentObject.EntityLoad()  
at Adecef.TelgatNGOSS.ObjectServer.ObjectFactory.GetManagedObject(String oid, String objectClass, Boolean isFromWeb)  
10-05-2018 00:00:01.2373 ERROR Thd: 6568 [ObjectServer] (processEvent) Exception Object reference not set to an instance of an object.  
System.NullReferenceException: Object reference not set to an instance of an object.  
at Adecef.TelgatNGOSS.ObjectServer.EventReportManager.processEvent(Object taskInfo)  
10-05-2018 00:00:08.6432 ERROR Thd: 6568 192.168.56.1 [ManagedObject] (EntityLoad) Object not be loaded 192.168.56.1 AGENT  
Adecef.TelgatNGOSS.ObjectServer.ManagedObjectException: instance does not exists  
at Adecef.TelgatNGOSS.ObjectServer.ManagedObject.EntityLoad()  
10-05-2018 00:00:08.6432 ERROR Thd: 6568 [ObjectServer] (GetManagedObject) Object can not be load: 192.168.56.1  
Adecef.TelgatNGOSS.ObjectServer.ManagedObjectException: instance does not exists  
at Adecef.TelgatNGOSS.ObjectServer.ManagedObject.EntityLoad()  
at Adecef.TelgatNGOSS.ObjectServer.MAgentObject.EntityLoad()  
at Adecef.TelgatNGOSS.ObjectServer.ObjectFactory.GetManagedObject(String oid, String objectClass, Boolean isFromWeb)  
10-05-2018 00:00:09.5814 ERROR Thd: 6568 [ObjectServer] (processEvent) Exception Object reference not set to an instance of an object.  
System.NullReferenceException: Object reference not set to an instance of an object.  
at Adecef.TelgatNGOSS.ObjectServer.EventReportManager.processEvent(Object taskInfo)  
10-05-2018 00:00:11.2221 ERROR Thd: 7156 192.168.56.1 [ManagedObject] (EntityLoad) Object not be loaded 192.168.56.1 AGENT  
Adecef.TelgatNGOSS.ObjectServer.ManagedObjectException: instance does not exists  
at Adecef.TelgatNGOSS.ObjectServer.ManagedObject.EntityLoad()

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 21, 2018, 9:23pm UTC](https://discuss.elastic.co/t/logstash-parsing-log-messages/132630/2 "2018-05-21T21:23:35Z")

</div>

The Logstash documentation contains an example of something very similar: [https://www.elastic.co/guide/en/logstash/current/multiline.html](https://www.elastic.co/guide/en/logstash/current/multiline.html)

---

<div class="post-metadata">

**Author:** ![Sunillinus](https://avatars.discourse-cdn.com/v4/letter/s/2bfe46/32.png) [@Sunillinus](https://discuss.elastic.co/u/Sunillinus)\
**Post date:** [May 22, 2018, 12:19pm UTC](https://discuss.elastic.co/t/logstash-parsing-log-messages/132630/3 "2018-05-22T12:19:39Z")

</div>

I have used multiline codec, but its not working as expected, I mean it is taking all lines between two lines, only it is taking 2 or 3 lines. And remaining lines are going with next event.

This is configuration file:

input {  
file {  
path =\> ["D:/Sample/\*"]  
start\_position =\> "beginning"   
sincedb\_path =\> "/dev/null"  
codec =\> multiline {  
pattern =\> "^(\s)"  
what =\> "previous"  
}  
}  
}

output {  
elasticsearch {  
hosts =\> ["localhost:9200"]  
index =\> "sample-%{+YYYY.MM.dd}"  
}  
stdout {}

}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 22, 2018, 1:04pm UTC](https://discuss.elastic.co/t/logstash-parsing-log-messages/132630/4 "2018-05-22T13:04:08Z")

</div>

Please show an example of the input and the resulting events. Use a `stdout { codec => rubydebug }` output to dump the raw events and make sure you format the example input as preformatted text.

---

<div class="post-metadata">

**Author:** ![Sunillinus](https://avatars.discourse-cdn.com/v4/letter/s/2bfe46/32.png) [@Sunillinus](https://discuss.elastic.co/u/Sunillinus)\
**Post date:** [May 23, 2018, 5:48am UTC](https://discuss.elastic.co/t/logstash-parsing-log-messages/132630/5 "2018-05-23T05:48:33Z")

</div>

@magnusbaeck

The Contents of my log file:

2018-05-10 00:00:00.0031 DEBUG Thd: 6540 [Schedule] (checkSchedules) Chequea a: 10/05/2018 12:00:00 AM ON  
2018-05-10 00:00:00.0031 DEBUG Thd: 6540 [Schedule] (checkSchedules) ThreadFinished: 00:00:00  
2018-05-10 00:00:01.1904 ERROR Thd: 6568 192.168.56.1 [ManagedObject] (EntityLoad) Object not be loaded 192.168.56.1 AGENT  
Adecef.TelgatNGOSS.ObjectServer.ManagedObjectException: instance does not exists  
at Adecef.TelgatNGOSS.ObjectServer.ManagedObject.EntityLoad()  
2018-05-10 00:00:01.1904 ERROR Thd: 6568 [ObjectServer] (GetManagedObject) Object can not be load: 192.168.56.1  
Adecef.TelgatNGOSS.ObjectServer.ManagedObjectException: instance does not exists  
at Adecef.TelgatNGOSS.ObjectServer.ManagedObject.EntityLoad()  
at Adecef.TelgatNGOSS.ObjectServer.MAgentObject.EntityLoad()  
at Adecef.TelgatNGOSS.ObjectServer.ObjectFactory.GetManagedObject(String oid, String objectClass, Boolean isFromWeb)

This is my Input

input {  
file {  
path =\> ["D:/TestLogs/tm\*"]  
start\_position =\> "beginning"   
sincedb\_path =\> "/dev/null"  
codec =\> multiline {  
pattern =\> "^(\s)"  
what =\> "previous"  
}  
}  
}

and the output got generated is shown below:

{  
"@timestamp" =\> 2018-05-23T04:56:10.448Z,  
"path" =\> "D:/TestLogs/tm20180510",  
"host" =\> "BALP-SunilS",  
"@version" =\> "1",  
"message" =\> "2018-05-10 00:00:01.1904\tERROR\tThd: 6568\t\t[ObjectServer]\t(GetManagedObject)\tObject can not be load: 192.168.56.1\r"  
}  
{  
"path" =\> "D:/TestLogs/tm20180510",  
"host" =\> "BALP-SunilS",  
"tags" =\> [  
[0] "multiline"  
],  
"message" =\> "Adecef.TelgatNGOSS.ObjectServer.ManagedObjectException: instance does not exists\r\n at Adecef.TelgatNGOSS.ObjectServer.ManagedObject.EntityLoad()\r",  
"@timestamp" =\> 2018-05-23T04:56:10.448Z,  
"@version" =\> "1"  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 23, 2018, 6:00am UTC](https://discuss.elastic.co/t/logstash-parsing-log-messages/132630/6 "2018-05-23T06:00:38Z")

</div>

I repeat: Make sure you format the example input as preformatted text. Use Markdown notation or the `</>` toolbar button.

But I can see in your output that the second line of the message doesn't begin with a whitespace character, it starts with "Adecef". That's why the multiline codec doesn't work. Have a look at this example instead: [https://www.elastic.co/guide/en/logstash/current/multiline.html#\_timestamps](https://www.elastic.co/guide/en/logstash/current/multiline.html#_timestamps)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 20, 2018, 6:00am UTC](https://discuss.elastic.co/t/logstash-parsing-log-messages/132630/7 "2018-06-20T06:00:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
