I want to make multiline pattern work but the snipped I used below is working only when I change input_type: log and NOT working with input_type:filesteam can someone please help me what I should change to make multiline work?
Hey, Yes I was able to follow that I need to use parsers but I am not able to figure out what exactly should I use to parse my text log files ( .txt) If you could help that would be great like I tried using - just wanted to combine 3500 lines together but this is not working please let me know what I can change here to make this work..thanks
well its not working with either of those lines_count and count_lines but other confusion I have is the multiline format described in this article is is like -
Hey, good news I got it working after few experiments one of which worked is basically combining the two snippets I posted - So in short I ended up writing parser but properties to match my use case for multiline
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.