# Multiline filter is not working even after installing the plugin

**URL:** https://discuss.elastic.co/t/multiline-filter-is-not-working-even-after-installing-the-plugin/325611
**Category:** Logstash
**Created:** [February 15, 2023, 12:39pm UTC](https://discuss.elastic.co/t/multiline-filter-is-not-working-even-after-installing-the-plugin/325611 "2023-02-15T12:39:48Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![Balaguru\_Maruthamuth](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/balaguru_maruthamuth/32/117301_2.png) [@Balaguru\_Maruthamuth](https://discuss.elastic.co/u/Balaguru_Maruthamuth)
#### Post date: [February 15, 2023, 12:39pm UTC](https://discuss.elastic.co/t/multiline-filter-is-not-working-even-after-installing-the-plugin/325611/1 "2023-02-15T12:39:48Z")

</div>

Warning: Manual override - there are filters that might not work with multiple worker threads {:pipeline\_id=\>"exterro", :worker\_threads=\>3, :filters=\>["multiline", "multiline", "multiline", "multiline", "multiline", "multiline", "multiline", "multiline", "multiline", "multiline", "multiline", "multiline", "multiline"], :thread=\>"#Thread:0x2b20cc95run"}

I have tried installing logstash-filter-multiline and logstash-codec-multiline and my configuration is as like below in filter.conf file

filter {  
if [type] == "tomcat"{  
multiline {  
pattern =\> "(\[1\]+(?:Error|Exception).+)|(^\s+at .+)|(^\s+... \d+ more)|(^\t+)|(^\s\*Caused by:.+)"  
what =\> "previous"  
}  
grok {  
match =\> { "source" =\> "%{GREEDYDATA}/%{GREEDYDATA:filename}.log" }  
}  
grok {  
match =\> { "source" =\> "%{GREEDYDATA}/%{GREEDYDATA:tenant}.log" }  
}  
mutate {  
lowercase =\> ["tenant"]  
}  
date {  
match =\> ["time", "yyyy-MM-dd-HH-mm-ss-SSS"]  
target =\> "@timestamp"  
}  
}  
}

and elasticsearch output conf file like below

output {  
if [type] == "tomcat"{  
opensearch {  
hosts =\> ["[https://es-url.region.amazonaws.com:443](https://es-url.region.amazonaws.com:443)"]  
user =\> ""  
password =\> ""  
index =\> "filebeat-%{tenantId}"  
ecs\_compatibility =\> disabled  
ssl\_certificate\_verification =\> false  
}  
}

After the configuration is updated logs output is not updating in kibana dashboard

Kindly help to resolve the same!

I am using AWS elasticsearch with filebeat and logstash installed on ec2.

* * *

1. a-zA-Z.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [February 15, 2023, 12:39pm UTC](https://discuss.elastic.co/t/multiline-filter-is-not-working-even-after-installing-the-plugin/325611/2 "2023-02-15T12:39:48Z")

</div>

OpenSearch/OpenDistro are AWS run products and differ from the original Elasticsearch and Kibana products that Elastic builds and maintains. You may need to contact them directly for further assistance.

(This is an automated response from your friendly Elastic bot. Please report this post if you have any suggestions or concerns :elasticheart: )

---

<div class="post-metadata">

### Author: ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)
#### Post date: [February 15, 2023, 12:44pm UTC](https://discuss.elastic.co/t/multiline-filter-is-not-working-even-after-installing-the-plugin/325611/3 "2023-02-15T12:44:36Z")

</div>

What is your input configuration and what is your filebeat configuration?

If you are using filebeat to send logs do Logstash, the multiline **needs** to be configured on filebeat, not on logstash.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [March 15, 2023, 12:44pm UTC](https://discuss.elastic.co/t/multiline-filter-is-not-working-even-after-installing-the-plugin/325611/4 "2023-03-15T12:44:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
