# Multiline pattern for javaserver log not working

**URL:** <https://discuss.elastic.co/t/multiline-pattern-for-javaserver-log-not-working/296803>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [February 10, 2022, 6:56am UTC](https://discuss.elastic.co/t/multiline-pattern-for-javaserver-log-not-working/296803 "2022-02-10T06:56:37Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![mangeshmj1992](https://avatars.discourse-cdn.com/v4/letter/m/d9b06d/32.png) [@mangeshmj1992](https://discuss.elastic.co/u/mangeshmj1992)\
**Post date:** [February 10, 2022, 6:56am UTC](https://discuss.elastic.co/t/multiline-pattern-for-javaserver-log-not-working/296803/1 "2022-02-10T06:56:37Z")

</div>

Hello team,  
I am trying to write multline pattern for below log line. But it is not working.  
It is displaying seperate line for each "at" record. Can you please help me on this to write multiline pattern

Log line:

```auto
[2022-02-10T00:02:06,971][ERROR][o.e.x.i.IndexLifecycleRunner] [es-master-1] policy [index-less-than-30-days] for index [akl-netsec-ctm-2022.01.11] failed on step [{"phase":"hot","action":"rollover","name":"check-rollover-ready"}]. Moving to ERROR step
java.lang.IllegalArgumentException: index.lifecycle.rollover_alias [akl-netsec-ctm] does not point to index [akl-netsec-ctm-2022.01.11]
        at org.elasticsearch.xpack.core.ilm.WaitForRolloverReadyStep.evaluateCondition(WaitForRolloverReadyStep.java:156) [x-pack-core-7.16.2.jar:7.16.2]
        at org.elasticsearch.xpack.ilm.IndexLifecycleRunner.runPeriodicStep(IndexLifecycleRunner.java:226) [x-pack-ilm-7.16.2.jar:7.16.2]
        at org.elasticsearch.xpack.ilm.IndexLifecycleService.triggerPolicies(IndexLifecycleService.java:408) [x-pack-ilm-7.16.2.jar:7.16.2]
        at org.elasticsearch.xpack.ilm.IndexLifecycleService.triggered(IndexLifecycleService.java:339) [x-pack-ilm-7.16.2.jar:7.16.2]
        at org.elasticsearch.xpack.core.scheduler.SchedulerEngine.notifyListeners(SchedulerEngine.java:186) [x-pack-core-7.16.2.jar:7.16.2]
        at org.elasticsearch.xpack.core.scheduler.SchedulerEngine$ActiveSchedule.run(SchedulerEngine.java:220) [x-pack-core-7.16.2.jar:7.16.2]
        at java.util.concurrent.Executors$RunnableAdapter.call(Executors.java:539) [?:?]
        at java.util.concurrent.FutureTask.run(FutureTask.java:264) [?:?]
        at java.util.concurrent.ScheduledThreadPoolExecutor$ScheduledFutureTask.run(ScheduledThreadPoolExecutor.java:304) [?:?]
        at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1136) [?:?]
        at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:635) [?:?]
        at java.lang.Thread.run(Thread.java:833) [?:?]

```

Multiline pattern:

```auto
  multiline.pattern: '^\[[0-9]{4}-[0-9]{2}-[0-9]{2}[T]{1}[0-9]{2}:[0-9]{2}:[0-9]{2}'
  multiline.negate: true
  multiline.match: after
  fields_under_root: true

```

---

<div class="post-metadata">

**Author:** ![marc.guasch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marc.guasch/32/74642_2.png) [@marc.guasch](https://discuss.elastic.co/u/marc.guasch)\
**Post date:** [February 10, 2022, 11:24am UTC](https://discuss.elastic.co/t/multiline-pattern-for-javaserver-log-not-working/296803/2 "2022-02-10T11:24:26Z")

</div>

Hello!

I tested a regexp similar to yours with no major problems. Since you did not post your full configuration I am going to guess that maybe you are using the `filestream` input and the `multiline` parser is not properly configured. If using the `log` input the config should look like:

```auto
- type: log
  enabled: true
  paths:
    - 'sample.log'
  multiline.pattern: '^\[[0-9]{4}-[0-9]{2}-[0-9]{2}T[0-9]{2}:[0-9]{2}:[0-9]{2}(,[0-9]{3})?'
  multiline.negate: true
  multiline.match: after
  fields_under_root: true

```

While if using the `filestream` input:

```auto
- type: filestream
  enabled: true
  paths:
    - 'sample.log'
  parsers:
    - multiline:
        pattern: '^\[[0-9]{4}-[0-9]{2}-[0-9]{2}T[0-9]{2}:[0-9]{2}:[0-9]{2}(,[0-9]{3})?'
        negate: true
        match: after
  fields_under_root: true

```

Hope that helps!

---

<div class="post-metadata">

**Author:** ![mangeshmj1992](https://avatars.discourse-cdn.com/v4/letter/m/d9b06d/32.png) [@mangeshmj1992](https://discuss.elastic.co/u/mangeshmj1992)\
**Post date:** [February 10, 2022, 12:05pm UTC](https://discuss.elastic.co/t/multiline-pattern-for-javaserver-log-not-working/296803/3 "2022-02-10T12:05:55Z")

</div>

Awesome it worked . Thank you so much I am trying this from last two days

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 10, 2022, 2:06pm UTC](https://discuss.elastic.co/t/multiline-pattern-for-javaserver-log-not-working/296803/4 "2022-03-10T14:06:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
