# Multiline pattern with grok filter

**URL:** <https://discuss.elastic.co/t/multiline-pattern-with-grok-filter/24056>\
**Category:** Logstash\
**Created:** [June 22, 2015, 6:57am UTC](https://discuss.elastic.co/t/multiline-pattern-with-grok-filter/24056 "2015-06-22T06:57:34Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Keshav\_Agarwal](https://avatars.discourse-cdn.com/v4/letter/k/898d66/32.png) [@Keshav\_Agarwal](https://discuss.elastic.co/u/Keshav_Agarwal)\
**Post date:** [June 22, 2015, 6:57am UTC](https://discuss.elastic.co/t/multiline-pattern-with-grok-filter/24056/1 "2015-06-22T06:57:34Z")

</div>

I am trying to use grok filter for getting multiline patterns in logstash. I've tried using the GRREDYDATA but it doesn't seem to work. Any other method I can opt for doing the multiline pattern match?

---

<div class="post-metadata">

**Author:** ![naveenz](https://avatars.discourse-cdn.com/v4/letter/n/ebca7d/32.png) [@naveenz](https://discuss.elastic.co/u/naveenz)\
**Post date:** [June 22, 2015, 5:58pm UTC](https://discuss.elastic.co/t/multiline-pattern-with-grok-filter/24056/2 "2015-06-22T17:58:02Z")

</div>

Would suggest you to test your grok pattern here - [http://grokconstructor.appspot.com/](http://grokconstructor.appspot.com/)

An example pattern like the one below worked fine for me:

%{TIMESTAMP\_ISO8601:logtime}%{SPACE}%{LOGLEVEL:loglevel}%{SPACE}%{NOTSPACE:threadname}%{SPACE}%{NOTSPACE:useremail}%{SPACE}(%{JAVAFILE:filename}:%{NUMBER:linenumber})%{SPACE}-%{SPACE}%{GREEDYDATA:logmessage}

Log message: 2015-06-14 00:15:07,763 ERROR [Timer-6] \<\> (xxxStatusUpdater.java:641) - xxxStatusUpdater.updatexxxStatuses: Generic Exception Getting Status From xxx! Year out of range.; nested exception is java.sql.BatchUpdateException: Year out of range.  
at org.springframework.jdbc.support.AbstractFallbackSQLExceptionTranslator.translate(AbstractFallbackSQLExceptionTranslator.java:83)  
at org.springframework.jdbc.support.AbstractFallbackSQLExceptionTranslator.translate(AbstractFallbackSQLExceptionTranslator.java:80)  
at org.springframework.jdbc.support.AbstractFallbackSQLExceptionTranslator.translate(AbstractFallbackSQLExceptionTranslator.java:80)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:36am UTC](https://discuss.elastic.co/t/multiline-pattern-with-grok-filter/24056/3 "2017-07-06T05:36:50Z")

</div>


