# Multiline patterns

**URL:** <https://discuss.elastic.co/t/multiline-patterns/232632>\
**Category:** Logstash\
**Created:** [May 14, 2020, 11:57am UTC](https://discuss.elastic.co/t/multiline-patterns/232632 "2020-05-14T11:57:52Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Satyajeet\_Singh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/satyajeet_singh/32/68332_2.png) [@Satyajeet\_Singh](https://discuss.elastic.co/u/Satyajeet_Singh)\
**Post date:** [May 14, 2020, 11:57am UTC](https://discuss.elastic.co/t/multiline-patterns/232632/1 "2020-05-14T11:57:52Z")

</div>

Hi Trying to create a config for logstash which can aggregate multiple lines with different pattern

example loglines:  
2020-05-14 13:43:05.222 SSL accepted cipher=ECDHE-RSA-AES128-SHA256  
2020-05-14 13:43:05.222 Connection protocol=TLSv1.2  
2020-05-14 13:43:05.225 [anonymous@xyz123.example.com]: Connected, connection id=7515, client id=, type: queue, UTC offset=3

all these lines should be logged once in logstash with all of the details together.  
in the config:

```auto
input {
  file {
    path => "/log/ems/tibems.log"
    type => "tibco"
    tags => ["jndi"]
    codec => multiline {
       pattern => "SSL accepted cipher"
       what => "next"
    }
  }
}

```

Above will aggregate the 1st two lines but not the 3rd line. How can we combine all 3 in one?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 14, 2020, 2:43pm UTC](https://discuss.elastic.co/t/multiline-patterns/232632/2 "2020-05-14T14:43:29Z")

</div>

If those are the only lines in the log then

```
pattern => "SSL accepted cipher"
negate => true
what => "previous"

```

should work.

---

<div class="post-metadata">

**Author:** ![Satyajeet\_Singh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/satyajeet_singh/32/68332_2.png) [@Satyajeet\_Singh](https://discuss.elastic.co/u/Satyajeet_Singh)\
**Post date:** [May 15, 2020, 7:50am UTC](https://discuss.elastic.co/t/multiline-patterns/232632/3 "2020-05-15T07:50:38Z")

</div>

These are not the only lines.  
These are the lines for SSL connection requests.

the setting which are suggesting is going to add any line which doesn't contain "SSL accepted cipher" to previous line. Which is not correct.

The 1st two lines should be added to 3rd line.

There will be startup logs which wont contain "[anonymous@xyz123.example.com](mailto:anonymous@xyz123.example.com)"  
and there will other non-ssl request which will only have [anonymous@xyz123.example.com](mailto:anonymous@xyz123.example.com) and not the previous lines with ssl details.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 15, 2020, 3:36pm UTC](https://discuss.elastic.co/t/multiline-patterns/232632/4 "2020-05-15T15:36:20Z")

</div>

If the three lines always come together then you could use alternation

```
pattern => "Connection protocol=|Connected, connection id="

```

If there are ever other lines interleaved then I do not think the problem is solvable in logstash.

---

<div class="post-metadata">

**Author:** ![Satyajeet\_Singh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/satyajeet_singh/32/68332_2.png) [@Satyajeet\_Singh](https://discuss.elastic.co/u/Satyajeet_Singh)\
**Post date:** [May 16, 2020, 6:42pm UTC](https://discuss.elastic.co/t/multiline-patterns/232632/5 "2020-05-16T18:42:05Z")

</div>

Thanks  
I tried

```auto
pattern => "SSL accepted cipher|Connection protocol"

```

it worked

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 13, 2020, 6:42pm UTC](https://discuss.elastic.co/t/multiline-patterns/232632/6 "2020-06-13T18:42:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
