# Logstash - Parsing Log Messages

**URL:** <https://discuss.elastic.co/t/logstash-parsing-log-messages/132630>\
**Category:** Logstash\
**Created:** [May 21, 2018, 8:37am UTC](https://discuss.elastic.co/t/logstash-parsing-log-messages/132630 "2018-05-21T08:37:11Z")\
**Posts on this page:** 1\
**Showing post:** 3

<div class="post-metadata">

**Author:** ![Sunillinus](https://avatars.discourse-cdn.com/v4/letter/s/2bfe46/32.png) [@Sunillinus](https://discuss.elastic.co/u/Sunillinus)\
**Post date:** [May 22, 2018, 12:19pm UTC](https://discuss.elastic.co/t/logstash-parsing-log-messages/132630/3 "2018-05-22T12:19:39Z")

</div>

I have used multiline codec, but its not working as expected, I mean it is taking all lines between two lines, only it is taking 2 or 3 lines. And remaining lines are going with next event.

This is configuration file:

input {  
file {  
path =\> ["D:/Sample/\*"]  
start\_position =\> "beginning"   
sincedb\_path =\> "/dev/null"  
codec =\> multiline {  
pattern =\> "^(\s)"  
what =\> "previous"  
}  
}  
}

output {  
elasticsearch {  
hosts =\> ["localhost:9200"]  
index =\> "sample-%{+YYYY.MM.dd}"  
}  
stdout {}

}

---

_[View the full topic](https://discuss.elastic.co/t/logstash-parsing-log-messages/132630)._
