# Losgstah configuration issue

**URL:** <https://discuss.elastic.co/t/losgstah-configuration-issue/36017>\
**Category:** Logstash\
**Created:** [December 1, 2015, 9:50am UTC](https://discuss.elastic.co/t/losgstah-configuration-issue/36017 "2015-12-01T09:50:53Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![fbicquelet](https://avatars.discourse-cdn.com/v4/letter/f/7cd45c/32.png) [@fbicquelet](https://discuss.elastic.co/u/fbicquelet)\
**Post date:** [December 1, 2015, 9:50am UTC](https://discuss.elastic.co/t/losgstah-configuration-issue/36017/1 "2015-12-01T09:50:53Z")

</div>

Hello,  
I begin with logstash and ElasticSearch and I would like to index .pdf or .doc file type in ElasticSearch via logstash.  
I configured logstash using the codec multiline to get my file in a single message in ElasticSearch . Below is my configuration file:

input {  
file {  
path =\> "D:/BaseCV/\*"  
codec =\> multiline {  
# Grok pattern names are valid! 🙂  
pattern =\> ""  
what =\> "previous"  
}

```
     }

```

}

output {  
stdout {  
codec =\> "rubydebug"  
}  
elasticsearch {  
hosts =\> "localhost"  
index =\> "cvindex"  
document\_type =\> "file"  
}  
}

At the start of logstash the first file I add , I recovered in ElasticSearch in one message , but the following are spread over several messages. I wish I had the correspondence : 1 file = 1 message.  
Is this possible ? What should I change my setup to solve the problem ?  
Thank you for your feedback.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [December 1, 2015, 9:54am UTC](https://discuss.elastic.co/t/losgstah-configuration-issue/36017/2 "2015-12-01T09:54:02Z")

</div>

Log stash does not support indexing of PDF and Word documents. For this instead look at the [mapper attachment plugin for Elasticsearch](https://www.elastic.co/guide/en/elasticsearch/plugins/current/mapper.html).

---

<div class="post-metadata">

**Author:** ![fbicquelet](https://avatars.discourse-cdn.com/v4/letter/f/7cd45c/32.png) [@fbicquelet](https://discuss.elastic.co/u/fbicquelet)\
**Post date:** [December 1, 2015, 10:08am UTC](https://discuss.elastic.co/t/losgstah-configuration-issue/36017/3 "2015-12-01T10:08:07Z")

</div>

Thanks for your answer.  
The plugin map attachment is already installed on my version 1.7.2 ElasticSearch, and I managed to index documents in ElasticSearch, but not always in a single message.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:20am UTC](https://discuss.elastic.co/t/losgstah-configuration-issue/36017/4 "2017-07-06T05:20:37Z")

</div>


