# Multiline log parsing

**URL:** <https://discuss.elastic.co/t/multiline-log-parsing/84251>\
**Category:** Logstash\
**Created:** [May 2, 2017, 11:42am UTC](https://discuss.elastic.co/t/multiline-log-parsing/84251 "2017-05-02T11:42:48Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![shammi](https://avatars.discourse-cdn.com/v4/letter/s/34f0e0/32.png) [@shammi](https://discuss.elastic.co/u/shammi)\
**Post date:** [May 2, 2017, 11:42am UTC](https://discuss.elastic.co/t/multiline-log-parsing/84251/1 "2017-05-02T11:42:48Z")

</div>

Hi,  
I am using grok pattern to get date from filename and that is working fine. Now i need to parse multiline log event along with date from filename.

Log:

8480 12:33:38 ERROR Error while rendering view: '/Views/Article/ads.cshtml' (model: 'Informa.Web.ViewModels.RelatedDealsModel, [Informa.Web](http://Informa.Web)').

Exception: System.InvalidOperationException  
Message: Error while rendering view: '/Views/Article/ArticleRelatedDeals.cshtml' (model: 'Informa.Web.ViewModels.ads.RelatedDealsModel, [Informa.Web](http://Informa.Web)').

Source: Sitecore.Mvc  
at Sitecore.Mvc.Presentation.ViewRenderer.Render(TextWriter writer)  
at Informa.Library.CustomSitecore.Pipelines.RenderRenderings.ExecuteRenderer.Render(Renderer renderer, TextWriter writer, RenderRenderingArgs args) in D:\jenkins\jobs\prodFE\workspace\src\Informa.Library\CustomSitecore\Pipelines\RenderRenderings\ExecuteRenderer.cs:line 21

Nested Exception

Exception: System.NullReferenceException  
Message: Object reference not set to an instance of an object.  
Source: Informa.Library  
at Informa.Library.Article.Companies.RelatedDealsService.b\_\_3\_2(Deal c) in D:\jenkins\jobs\prodFE\workspace\src\Informa.Library\Article\Companies\RelatedDealsService.cs:line 29  
at System.Linq.Enumerable.WhereSelectArrayIterator`2.MoveNext()  
at ASP.\_Page\_Views\_Article\_ArticleRelatedDeals\_cshtml.Execute() in D:\inetpub\wwwroot\INFORMA\Website\Views\Article\ArticleRelatedDeals.cshtml:line 8  
at System.Web.WebPages.WebPageBase.ExecutePageHierarchy()  
at System.Web.Mvc.WebViewPage.ExecutePageHierarchy()  
at System.Web.WebPages.WebPageBase.ExecutePageHierarchy(WebPageContext pageContext, TextWriter writer, WebPageRenderingBase startPage)  
at System.Web.Mvc.Html.PartialExtensions.Partial(HtmlHelper htmlHelper, String partialViewName, Object model, ViewDataDictionary viewData)  
at Sitecore.Mvc.Presentation.ViewRenderer.Render(TextWriter writer)

Please suggest grok to parse this multiline log.

---

<div class="post-metadata">

**Author:** ![shammi](https://avatars.discourse-cdn.com/v4/letter/s/34f0e0/32.png) [@shammi](https://discuss.elastic.co/u/shammi)\
**Post date:** [May 3, 2017, 7:31am UTC](https://discuss.elastic.co/t/multiline-log-parsing/84251/2 "2017-05-03T07:31:10Z")

</div>

I am using filebeat.yml as:  
-  
paths:  
- /app/logs/sitecore/log.\*  
input\_type: log  
document\_type: sitecore\_log  
pattern: '[[:digit:]]{4}[[:space:]][[:digit:]]{2}:[[:digit:]]{2}:[[:digit:]]{2}'  
negate: true  
match: next

logstash config:

```
 if [type] == "sitecore_log" {
    multiline {
      patterns_dir => "/etc/logstash/conf.d/patterns"
      pattern => "(^%{INT})|(^%{WORD})"
      negate => "true"
      what => "next"
    }
        grok {
         patterns_dir => ["/etc/logstash/conf.d/patterns"]
         match => ["message", "(%{INT:pid}|%{WORD:heartbeat}) %{TIME:time} %{LOGLEVEL:loglevel} (%{GREEDY_DATA:sitecore_log}|%{GREEDY_DATA:rewrite_log})"]
             }
        grok {
        match => ["source", "(%{YEAR:year}%{MONTHNUM:month}%{MONTHDAY:day}\.%{HOUR:hour}%{MINUTE:minute}%{SECOND:second}\.txt$)"]
        add_field => ["timestamp", "%{year}-%{month}-%{day} %{time}"]
         }
        mutate {
        remove_field => ["year", "month", "day", "hour", "minute", "second"]
                }
        date {
        match => ["timestamp", "yyyy-MM-dd HH:mm:ss", "yyyy-MM-dd HH:mm:ss.SSSZ"]
        target => "@timestamp"
        }
        mutate {
        gsub => [
        "message","\n"," ",
        "message","\r",""
                ]
         }
   }
```

---

<div class="post-metadata">

**Author:** ![shammi](https://avatars.discourse-cdn.com/v4/letter/s/34f0e0/32.png) [@shammi](https://discuss.elastic.co/u/shammi)\
**Post date:** [May 8, 2017, 7:14am UTC](https://discuss.elastic.co/t/multiline-log-parsing/84251/3 "2017-05-08T07:14:10Z")

</div>

Thanks. This has been fixed. 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 5, 2017, 7:18am UTC](https://discuss.elastic.co/t/multiline-log-parsing/84251/4 "2017-06-05T07:18:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
