# Multiline not reading all lines?

**URL:** <https://discuss.elastic.co/t/multiline-not-reading-all-lines/36762>\
**Category:** Logstash\
**Created:** [December 9, 2015, 3:42pm UTC](https://discuss.elastic.co/t/multiline-not-reading-all-lines/36762 "2015-12-09T15:42:00Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![CraigFoote](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/craigfoote/32/4571_2.png) [@CraigFoote](https://discuss.elastic.co/u/CraigFoote)\
**Post date:** [December 9, 2015, 3:42pm UTC](https://discuss.elastic.co/t/multiline-not-reading-all-lines/36762/1 "2015-12-09T15:42:00Z")

</div>

I have some logs all starting with a timestamp, javaclass, log level and then a message, some of them multiline.  
I'm just starting with a couple single-line events first. I have two of them in a file and I have the following config:

> ```
> input{
> file{
> path => "/path/to/log"
> start_position => "beginning"
> sincedb_path => "/dev/null"
> codec => multiline{
> # not starting with a timestamp should be merged with the previous line
> pattern => "^%{TIMESTAMP_ISO8601}"
> negate => true
> what => "previous"
> }
> }
> }
> filter{
> grok{
> match => { "message" => "\A%{TIMESTAMP_ISO8601}%{SPACE}%{JAVACLASS} \[%{LOGLEVEL}] %{GREEDYDATA}" }
> }
> }
> output{
> stdout{codec => rubydebug}
> }
> 
> ```

When I run it prints out the first event but not the second. I checked the files and both have a hard return at the end of their line. I've even added a third, empty line to see if it would force the display of the second event but it didn't. What am I doing wrong?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 9, 2015, 6:39pm UTC](https://discuss.elastic.co/t/multiline-not-reading-all-lines/36762/2 "2015-12-09T18:39:07Z")

</div>

The problem is that Logstash can't know until it gets the next physical line that begins with a timestamp that the current logical line is finished and should be flushed. I think [https://github.com/logstash-plugins/logstash-codec-multiline/issues/11](https://github.com/logstash-plugins/logstash-codec-multiline/issues/11) is the best issue to follow for tracking this limitation.

---

<div class="post-metadata">

**Author:** ![CraigFoote](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/craigfoote/32/4571_2.png) [@CraigFoote](https://discuss.elastic.co/u/CraigFoote)\
**Post date:** [December 9, 2015, 7:07pm UTC](https://discuss.elastic.co/t/multiline-not-reading-all-lines/36762/3 "2015-12-09T19:07:25Z")

</div>

Thanks Magnus, makes sense.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:19am UTC](https://discuss.elastic.co/t/multiline-not-reading-all-lines/36762/4 "2017-07-06T05:19:17Z")

</div>


