# Multi-Line Codec Help

**URL:** <https://discuss.elastic.co/t/multi-line-codec-help/126071>\
**Category:** Logstash\
**Created:** [March 29, 2018, 10:22am UTC](https://discuss.elastic.co/t/multi-line-codec-help/126071 "2018-03-29T10:22:26Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![cawoodm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cawoodm/32/14083_2.png) [@cawoodm](https://discuss.elastic.co/u/cawoodm)\
**Post date:** [March 29, 2018, 10:22am UTC](https://discuss.elastic.co/t/multi-line-codec-help/126071/1 "2018-03-29T10:22:26Z")

</div>

We need some help with the multiline codec.

We have syslog entries arriving - the message lines look like this:

```
jvm 1 : ERROR [fooHTTP38] [10.1.102.49] [AbstractResource] Error crea
jvm 1 : de.foo.platform.webservices.BadRequestException: Error creati
jvm 1 : at de.foo.platform.webservices.HttpPutResponseBuilder.cre
jvm 1 : Caused by: de.foo.platform.servicelayer.exceptions.ModelSav
jvm 1 : at de.foo.platform.servicelayer.internal.model.impl.wrapp
jvm 1 : at de.foo.platform.servicelayer.internal.model.impl.wrapp
jvm 1 : at de.foo.platform.servicelayer.internal.model.extractor.
jvm 1 : at de.foo.platform.servicelayer.internal.model.impl.Defau
jvm 1 : at de.foo.platform.servicelayer.internal.model.impl.Defau
jvm 1 : at de.foo.platform.servicelayer.internal.model.impl.Defau
jvm 1 : at de.foo.platform.servicelayer.internal.model.impl.Defau
jvm 1 : at de.foo.platform.webservices.AbstractYResource.createOr
jvm 1 : at de.foo.platform.webservices.HttpPutResponseBuilder.cre
jvm 1 : at de.foo.platform.webservices.HttpPutResponseBuilder.cre
jvm 1 : ... 101 more

```

Each line is logged separately as "INFO" but actually this is one event of type ERROR - the first line is the event and the other lines are multi-lines belonging to the event.

Our first challenge is to parse this with the multiline codec. We have seen that all events start with either ERROR, WARN, INFO, DEBUG etc. We have tried the following in our syslog input section:

```
codec => multiline {
    #Every line which doesn't contain this is a continuation of the previous event:
     pattern => "(SEVERE)|(ERROR)|(WARN)|(INFO)|(DEBUG)"
     negate => true
    what => "previous"
}

```

This does not work - we get no events in our output although the RegEx is apparently valid.

---

<div class="post-metadata">

**Author:** ![Dvikas](https://avatars.discourse-cdn.com/v4/letter/d/a9adbd/32.png) [@Dvikas](https://discuss.elastic.co/u/Dvikas)\
**Post date:** [March 29, 2018, 12:36pm UTC](https://discuss.elastic.co/t/multi-line-codec-help/126071/2 "2018-03-29T12:36:02Z")

</div>

multiline features u can do in filebeat,if you are using it.for eg:

### Multiline options

# Mutiline can be used for log messages spanning multiple lines. This is common

# for Java Stack Traces or C-Line Continuation

# The regexp Pattern that has to be matched. The example pattern matches all lines starting with [

multiline.pattern: provide the start of the line.I mean if your line starts with ####,please provide '^####'

# Defines if the pattern set under pattern should be negated or not. Default is false.

multiline.negate: true

# Match can be set to "after" or "before". It is used to define if lines should be append to a pattern

# that was (not) matched before or after or as long as a pattern is not matched based on negate.

# Note: After is the equivalent to previous and before is the equivalent to to next in Logstash

multiline.match: after

---

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [March 29, 2018, 2:57pm UTC](https://discuss.elastic.co/t/multi-line-codec-help/126071/3 "2018-03-29T14:57:49Z")

</div>

I don't believe you need the parenthesis around each of the values. Have you tried just `pattern => "SEVERE|ERROR|WARN|INFO|DEBUG"` ?

---

<div class="post-metadata">

**Author:** ![cawoodm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cawoodm/32/14083_2.png) [@cawoodm](https://discuss.elastic.co/u/cawoodm)\
**Post date:** [April 11, 2018, 12:55pm UTC](https://discuss.elastic.co/t/multi-line-codec-help/126071/4 "2018-04-11T12:55:25Z")

</div>

Yes, that seems to help thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 9, 2018, 12:55pm UTC](https://discuss.elastic.co/t/multi-line-codec-help/126071/5 "2018-05-09T12:55:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
