# Multiline conf file to parse log file to elasticsearch

**URL:** <https://discuss.elastic.co/t/multiline-conf-file-to-parse-log-file-to-elasticsearch/1153>\
**Category:** Logstash\
**Created:** [May 22, 2015, 7:37am UTC](https://discuss.elastic.co/t/multiline-conf-file-to-parse-log-file-to-elasticsearch/1153 "2015-05-22T07:37:39Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 22, 2015, 7:55am UTC](https://discuss.elastic.co/t/multiline-conf-file-to-parse-log-file-to-elasticsearch/1153/2 "2015-05-22T07:55:16Z")

</div>

With

```
multiline {
  pattern => "^."
  negate => true
  what => "previous"
}

```

it looks like you're trying to join a line with its predecessor unless the line it blank, correct? Are there actually empty lines between each entry? Your example only contains a single entry with no terminating blank line.

Secondly, if this is the last entry in a file it's hard for Logstash to know if it has seen all of the message and should ship what it has collected. See [LOGSTASH-512](https://logstash.jira.com/browse/LOGSTASH-512).

Finally, make sure [New to logstash: file input and stdout output not working](https://discuss.elastic.co/t/new-to-logstash-file-input-and-stdout-output-not-working/1140/2) doesn't apply in your case.

---

_[View the full topic](https://discuss.elastic.co/t/multiline-conf-file-to-parse-log-file-to-elasticsearch/1153)._
