# Multiline configuration for golang panic stacktraces

**URL:** <https://discuss.elastic.co/t/multiline-configuration-for-golang-panic-stacktraces/192071>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [July 24, 2019, 3:18pm UTC](https://discuss.elastic.co/t/multiline-configuration-for-golang-panic-stacktraces/192071 "2019-07-24T15:18:00Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![bschaeffer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bschaeffer/32/40303_2.png) [@bschaeffer](https://discuss.elastic.co/u/bschaeffer)\
**Post date:** [July 24, 2019, 3:18pm UTC](https://discuss.elastic.co/t/multiline-configuration-for-golang-panic-stacktraces/192071/1 "2019-07-24T15:18:00Z")

</div>

Has anyone come up with a `multiline` configuration for matching golang panic stacktraces?

FWIW, an example:

```
fatal error: runtime: out of memory

runtime stack:
runtime.throw(0x10daffb, 0x16)
        /tools/go/src/runtime/panic.go:608 +0x72
runtime.sysMap(0xdc84000000, 0x4000000, 0x1c04918)
        /tools/go/src/runtime/mem_linux.go:156 +0xc7
runtime.(*mheap).sysAlloc(0x1beaec0, 0x4000000, 0x435d5c, 0xc00503d800)
        /tools/go/src/runtime/malloc.go:619 +0x1c7
runtime.(*mheap).grow(0x1beaec0, 0x1, 0x0)
        /tools/go/src/runtime/mheap.go:920 +0x42
runtime.(*mheap).allocSpanLocked(0x1beaec0, 0x1, 0x1c04928, 0x400)
        /tools/go/src/runtime/mheap.go:848 +0x337
runtime.(*mheap).alloc_m(0x1beaec0, 0x1, 0x8, 0x7f9ad9810fff)
        /tools/go/src/runtime/mheap.go:692 +0x119
runtime.(*mheap).alloc.func1()
        /tools/go/src/runtime/mheap.go:759 +0x4c
runtime.(*mheap).alloc(0x1beaec0, 0x1, 0x7f9ad9010008, 0x7f9b8a47a1d8)
        /tools/go/src/runtime/mheap.go:758 +0x8a
runtime.(*mcentral).grow(0x1bec3f8, 0x0)
        /tools/go/src/runtime/mcentral.go:232 +0x94
runtime.(*mcentral).cacheSpan(0x1bec3f8, 0x7f9b8a47a1d8)
        /tools/go/src/runtime/mcentral.go:106 +0x2f8
runtime.(*mcache).refill(0x7fa3e86b1aa0, 0xc000091908)
        /tools/go/src/runtime/mcache.go:122 +0x95
runtime.(*mcache).nextFree.func1()
        /tools/go/src/runtime/malloc.go:749 +0x32
runtime.systemstack(0x0)
        /tools/go/src/runtime/asm_amd64.s:351 +0x66
runtime.mstart()
        /tools/go/src/runtime/proc.go:1229
```

---

<div class="post-metadata">

**Author:** ![justkind](https://avatars.discourse-cdn.com/v4/letter/j/919ad9/32.png) [@justkind](https://discuss.elastic.co/u/justkind)\
**Post date:** [July 25, 2019, 4:00pm UTC](https://discuss.elastic.co/t/multiline-configuration-for-golang-panic-stacktraces/192071/2 "2019-07-25T16:00:30Z")

</div>

Hmm not sure about the whitespace line but this multiline pattern seems to work on the go playground:

> ^runtime stack|^runtime.|/tools|^$

> **[Go Playground - The Go Programming Language](https://go.dev/play/p/lAwqylvmYIW)**

It should match the whitespace line and all the runtime stack, runtime._, and /tools_ lines underneath the fatal error one

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 22, 2019, 4:00pm UTC](https://discuss.elastic.co/t/multiline-configuration-for-golang-panic-stacktraces/192071/3 "2019-08-22T16:00:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
