Multiline codec in elasticsearch

From filebeat multiline are sent as follows .

Wed Feb 01 17:54:00 2017
ORA-xxxx: message
ORA-xxxx: message

This ORA line can be any numbers ( no definite) how do i use the ingest grok processor pattern?

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.