# Logstash pluguin to march multiline logs?

**URL:** <https://discuss.elastic.co/t/logstash-pluguin-to-march-multiline-logs/186399>\
**Category:** Logstash\
**Created:** [June 19, 2019, 7:29am UTC](https://discuss.elastic.co/t/logstash-pluguin-to-march-multiline-logs/186399 "2019-06-19T07:29:30Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![gerard.ramos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gerard.ramos/32/46958_2.png) [@gerard.ramos](https://discuss.elastic.co/u/gerard.ramos)\
**Post date:** [June 19, 2019, 7:29am UTC](https://discuss.elastic.co/t/logstash-pluguin-to-march-multiline-logs/186399/1 "2019-06-19T07:29:30Z")

</div>

Hello everyone, I was trying to send logs to Elasticsearch, this logs are in a file and they are multiline like this:

ERROR 2019-06-18 05:00:15,919 [pool-1-thread-147] somelongtexthere moretext moretext  
some text  
some text  
more text  
more text  
some text

ERROR 2019-06-18 05:00:15,919 [pool-1-thread-474] somelongtexthere moretext moretext

I was searching for a pluguin that can match a message every time that read ^%{LOGLEVEL} %{TIMESTAMP\_ISO8601}. I tried multiline pluguin but it dosn't worked for me, i think is because it needs a pattern in every line of the log. Any ideas???

Sorry for my english level and thanks for your time.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 19, 2019, 12:56pm UTC](https://discuss.elastic.co/t/logstash-pluguin-to-march-multiline-logs/186399/2 "2019-06-19T12:56:35Z")

</div>

```
file {
    path => "/home/user/foo.txt"
    sincedb_path => "/dev/null"
    start_position => beginning
    codec => multiline {
        pattern => "^%{LOGLEVEL} %{TIMESTAMP_ISO8601} "
        negate => true
        what => previous
        auto_flush_interval => 1
    }
}
```

---

<div class="post-metadata">

**Author:** ![gerard.ramos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gerard.ramos/32/46958_2.png) [@gerard.ramos](https://discuss.elastic.co/u/gerard.ramos)\
**Post date:** [June 19, 2019, 3:20pm UTC](https://discuss.elastic.co/t/logstash-pluguin-to-march-multiline-logs/186399/3 "2019-06-19T15:20:30Z")

</div>

Thiis filter goes inseide the input? Like this:

input {  
beats {  
port =\> 5443  
type =\> 'log'  
}  
stdin {  
path =\> "C:\Program Files\Mirth Connect\logs\mirth.log\*"  
sincedb\_path =\> "/dev/null"  
start\_position =\> beginning  
codec =\> multiline {  
pattern =\> "^%{LOGLEVEL} %{TIMESTAMP\_ISO8601} "  
negate =\> true  
what =\> previous  
auto\_flush\_interval =\> 1  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 19, 2019, 3:38pm UTC](https://discuss.elastic.co/t/logstash-pluguin-to-march-multiline-logs/186399/4 "2019-06-19T15:38:06Z")

</div>

Yes, but it would be a file input, not a stdin input. And you need to use forward slash in the path option of a file input, not backslash.

---

<div class="post-metadata">

**Author:** ![gerard.ramos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gerard.ramos/32/46958_2.png) [@gerard.ramos](https://discuss.elastic.co/u/gerard.ramos)\
**Post date:** [July 1, 2019, 7:50am UTC](https://discuss.elastic.co/t/logstash-pluguin-to-march-multiline-logs/186399/5 "2019-07-01T07:50:31Z")

</div>

I have modified the input file like this:

input {  
beats {  
port =\> 5443  
type =\> 'eventlog'  
}  
file {  
path =\> "C:/Program Files/Mirth Connect/logs/mirth\*"  
sincedb\_path =\> "/dev/null"  
start\_position =\> beginning  
codec =\> multiline {  
pattern =\> "^%{LOGLEVEL} %{TIMESTAMP\_ISO8601} "  
negate =\> true  
what =\> previous  
auto\_flush\_interval =\> 1  
}  
}  
}

Now kivana dont get logs, any idea??

---

<div class="post-metadata">

**Author:** ![Miguel1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/miguel1/32/82094_2.png) [@Miguel1](https://discuss.elastic.co/u/Miguel1)\
**Post date:** [July 1, 2019, 8:25am UTC](https://discuss.elastic.co/t/logstash-pluguin-to-march-multiline-logs/186399/6 "2019-07-01T08:25:14Z")

</div>

Your are using

```auto
sincedb_path => "/dev/null"

```

But as far as you are using Windows, at least your path looks like this, you should go for

```auto
sincedb_path => "NUL"

```

If not, it will not reparse the log.

---

<div class="post-metadata">

**Author:** ![gerard.ramos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gerard.ramos/32/46958_2.png) [@gerard.ramos](https://discuss.elastic.co/u/gerard.ramos)\
**Post date:** [July 1, 2019, 11:35am UTC](https://discuss.elastic.co/t/logstash-pluguin-to-march-multiline-logs/186399/7 "2019-07-01T11:35:12Z")

</div>

Oh well, I misunderstood it. I thought that the path referred to the origin of the logs. Now i have and the logs arrive:  
path =\> "/home/administrator/foo.txt"  
sincedb\_path =\> "/dev/null"

but the messages keep coming apart and the multiline codec dont work. I don't know if is important but the logstash also recive Winlogbeat messages to.

---

<div class="post-metadata">

**Author:** ![gerard.ramos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gerard.ramos/32/46958_2.png) [@gerard.ramos](https://discuss.elastic.co/u/gerard.ramos)\
**Post date:** [July 2, 2019, 11:27am UTC](https://discuss.elastic.co/t/logstash-pluguin-to-march-multiline-logs/186399/8 "2019-07-02T11:27:46Z")

</div>

I raise a more complete example (the line starts at the log level). I hope you can help me.

```
        ERROR 2019-06-29 09:36:42,548 [pool-2-thread-975] com.mirth.connect.server.userutil.MessageObject: The messageObject.getRawData() method is deprecated and will soon be removed. Please use connectorMessage.getRawData() instead.
        ERROR 2019-06-29 09:36:42,548 [pool-2-thread-975] com.mirth.connect.server.userutil.ResponseFactory: The getSuccessResponse(message) method is deprecated and will soon be removed. Please use getSentResponse(message) instead.
        ERROR 2019-06-29 09:39:17,620 [pool-2-thread-985] transformer: TypeError: Cannot read property "CX.1" from undefined
        ERROR 2019-06-29 09:39:18,937 [pool-2-thread-975] com.mirth.connect.server.userutil.ResponseFactory: The getSuccessResponse(message) method is deprecated and will soon be removed. Please use getSentResponse(message) instead.
        ERROR 2019-06-29 09:39:19,844 [pool-2-thread-975] com.mirth.connect.server.controllers.DonkeyEngineController: Could not find channel to route to: 1cf4c805-3cfc-4676-3e93-8b39b2d6464567
        com.mirth.connect.donkey.server.channel.ChannelException
        	at com.mirth.connect.server.controllers.DonkeyEngineController.dispatchRawMessage(DonkeyEngineController.java:511)
        	at com.mirth.connect.server.userutil.VMRouter.routeMessageByChannelId(VMRouter.java:164)
        	at com.mirth.connect.server.userutil.VMRouter.routeMessageByChannelId(VMRouter.java:149)
        	at com.mirth.connect.server.transformers.JavaScriptResponseTransformer$ResponseTransformerTask.call(JavaScriptResponseTransformer.java:110)
        	at java.util.concurrent.FutureTask.run(Unknown Source)
        	at java.util.concurrent.ThreadPoolExecutor.runWorker(Unknown Source)
        	at java.util.concurrent.ThreadPoolExecutor$Worker.run(Unknown Source)
        	at java.lang.Thread.run(Unknown Source)
        ERROR 2019-06-29 09:39:19,844 [pool-2-thread-975] com.mirth.connect.server.userutil.VMRouter: Error routing message to channel id: 1cf4c80f-3cfc-4486-8e93-8b39b2d65313123b537
        com.mirth.connect.donkey.server.channel.ChannelException
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 2, 2019, 12:58pm UTC](https://discuss.elastic.co/t/logstash-pluguin-to-march-multiline-logs/186399/9 "2019-07-02T12:58:24Z")

</div>

You have left something out. With that input, and that multiline codec I get

```
   "message" => "ERROR 2019-06-29 09:36:42,548 [pool-2-thread-975] com.mirth.connect.server.userutil.MessageObject: The messageObject.getRawData() method is deprecated and will soon be removed. Please use connectorMessage.getRawData() instead.",
   "message" => "ERROR 2019-06-29 09:36:42,548 [pool-2-thread-975] com.mirth.connect.server.userutil.ResponseFactory: The getSuccessResponse(message) method is deprecated and will soon be removed. Please use getSentResponse(message) instead.",
   "message" => "ERROR 2019-06-29 09:39:17,620 [pool-2-thread-985] transformer: TypeError: Cannot read property \"CX.1\" from undefined",
   "message" => "ERROR 2019-06-29 09:39:18,937 [pool-2-thread-975] com.mirth.connect.server.userutil.ResponseFactory: The getSuccessResponse(message) method is deprecated and will soon be removed. Please use getSentResponse(message) instead.",
   "message" => "ERROR 2019-06-29 09:39:19,844 [pool-2-thread-975] com.mirth.connect.server.controllers.DonkeyEngineController: Could not find channel to route to: 1cf4c805-3cfc-4676-3e93-8b39b2d6464567\ncom.mirth.connect.donkey.server.channel.ChannelException\n at com.mirth.connect.server.controllers.DonkeyEngineController.dispatchRawMessage(DonkeyEngineController.java:511)\n at com.mirth.connect.server.userutil.VMRouter.routeMessageByChannelId(VMRouter.java:164)\n at com.mirth.connect.server.userutil.VMRouter.routeMessageByChannelId(VMRouter.java:149)\n at com.mirth.connect.server.transformers.JavaScriptResponseTransformer$ResponseTransformerTask.call(JavaScriptResponseTransformer.java:110)\n at java.util.concurrent.FutureTask.run(Unknown Source)\n at java.util.concurrent.ThreadPoolExecutor.runWorker(Unknown Source)\n at java.util.concurrent.ThreadPoolExecutor$Worker.run(Unknown Source)\n at java.lang.Thread.run(Unknown Source)",

```

Which means the multiline codec works if the messages have the format that you say they do.

---

<div class="post-metadata">

**Author:** ![gerard.ramos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gerard.ramos/32/46958_2.png) [@gerard.ramos](https://discuss.elastic.co/u/gerard.ramos)\
**Post date:** [July 2, 2019, 2:44pm UTC](https://discuss.elastic.co/t/logstash-pluguin-to-march-multiline-logs/186399/10 "2019-07-02T14:44:01Z")

</div>

I'm really trying to find my fault but I do not see it, I pass the filter again in case you see it. Can it be a filebeat problem? Can the filter fail with the logs of other servers? Thank you for your answers

```
input {
  beats {
    port => 5443
    type => 'eventlog'
  }
  file {
    path => "/home/user/foo.txt"
    sincedb_path => "/dev/null"
    start_position => beginning
    codec => multiline {
      pattern => "^%{LOGLEVEL} %{TIMESTAMP_ISO8601} "
      negate => true
      what => previous
      auto_flush_interval => 1
    }
  }
}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 30, 2019, 2:44pm UTC](https://discuss.elastic.co/t/logstash-pluguin-to-march-multiline-logs/186399/11 "2019-07-30T14:44:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
