# Multiline plugin not working as expected

**URL:** <https://discuss.elastic.co/t/multiline-plugin-not-working-as-expected/46623>\
**Category:** Logstash\
**Created:** [April 7, 2016, 5:44am UTC](https://discuss.elastic.co/t/multiline-plugin-not-working-as-expected/46623 "2016-04-07T05:44:30Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sameer\_Panicker](https://avatars.discourse-cdn.com/v4/letter/s/d9b06d/32.png) [@Sameer\_Panicker](https://discuss.elastic.co/u/Sameer_Panicker)\
**Post date:** [April 7, 2016, 5:44am UTC](https://discuss.elastic.co/t/multiline-plugin-not-working-as-expected/46623/1 "2016-04-07T05:44:30Z")

</div>

I wanted individual field as a Logstash output. i.e. EventID, Level, Session ID, etc. My GROK pattern works fine on "[https://grokdebug.herokuapp.com/](https://grokdebug.herokuapp.com/)" where individual values are extracted. But when placed in logstash, my output is just a message

LS Output -

```
   "message" => "EventId : 1, Level : Informational, Message : Request, Payl

```

oad : [sessionID : 3e4ad1b0-2d2d-4f77-90b3-6315aacfacb7] [ipAddress : 157.109.26.92] [method : GET] [requestUri : [http://server001:8080/WebService](http://server001:8080/WebService)  
/api/products/48069/location/123] [content :] , EventName : Requ  
estInfo, Timestamp : 2016-04-05T14:35:36.4947170Z, ProcessId : 8924, ThreadId :  
7000\r\n\r",

My Actual Log -

EventId : 1, Level : Informational, Message : Request, Payload : [sessionID : 3e4ad1b0-2d2d-4f77-90b3-6315aacfacb7] [ipAddress : 157.109.26.92] [method : GET] [requestUri : [http://server001:8080/WebService/api/products/48069/location/123](http://server001:8080/WebService/api/products/48069/location/123)] [content :] , EventName :  
RequestInfo, Timestamp : 2016-04-05T14:35:36.4947170Z, ProcessId : 8924, ThreadId : 6996

Logstash Config File -

input  
{  
file  
{  
path =\> "C:/Logs/\*"  
codec =\> multiline  
{  
pattern =\> "%{WORD:EventId} : %{NUMBER:EventID}, %{WORD:Level} : %{WORD:EventLevel}, %{WORD:Message} : %{WORD:Operation}, %{WORD:Payload} : [%{WORD:Session\_ID} : %{UUID:SessionID}] [%{WORD:IPAddress} : %{IPORHOST:ClientIPAddress}] [%{WORD:Method} : %{WORD:HTTP\_Verb}] [%{WORD:requestUri} : %{URI:URL}] [%{WORD:content} : %{DATA:Request}] , %{WORD:EventName} : %{WORD:EventNameValue}, %{WORD:Timestamp} : %{TIMESTAMP\_ISO8601:Request\_DateTime}, %{WORD:ProcessId} : %{NUMBER:ProcessID}, %{WORD:ThreadID} : %{NUMBER:ThreadID}"  
what =\> next  
}  
}  
}

output  
{  
elasticsearch  
{  
hosts =\> ["myesserver:9200"]  
}  
stdout  
{  
codec =\> rubydebug  
}  
}

What should I do here ?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 7, 2016, 5:52am UTC](https://discuss.elastic.co/t/multiline-plugin-not-working-as-expected/46623/2 "2016-04-07T05:52:29Z")

</div>

The multiline codec doesn't extract fields, it only joins lines. You still need a grok filter.

---

<div class="post-metadata">

**Author:** ![Sameer\_Panicker](https://avatars.discourse-cdn.com/v4/letter/s/d9b06d/32.png) [@Sameer\_Panicker](https://discuss.elastic.co/u/Sameer_Panicker)\
**Post date:** [April 7, 2016, 6:00am UTC](https://discuss.elastic.co/t/multiline-plugin-not-working-as-expected/46623/3 "2016-04-07T06:00:02Z")

</div>

Thanks. That worked. Previously, it was not working.

I have one question, How can I have multiple grok patterns in one match =\> line.

GROK 1 - %{WORD:EventId} : %{NUMBER:EventID}, %{WORD:Level} : %{WORD:EventLevel}  
GROK 2 - %{WORD:EventId} : %{NUMBER:EventID}, %{WORD:Level} : %{WORD:EventLevel}, %{WORD:Payload} : [%{WORD:Session\_ID} : %{UUID:SessionID}]

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 7, 2016, 6:10am UTC](https://discuss.elastic.co/t/multiline-plugin-not-working-as-expected/46623/4 "2016-04-07T06:10:11Z")

</div>

See the example in the documentation of the [`match` option](https://www.elastic.co/guide/en/logstash/current/plugins-filters-grok.html#plugins-filters-grok-match).

In your example you could do it with a single expression too by making the last parts optional with `(...)?`:

```
GROK 2 - %{WORD:EventId} : %{NUMBER:EventID}, %{WORD:Level} : %{WORD:EventLevel}(, %{WORD:Payload} : \[%{WORD:Session_ID} : %{UUID:SessionID}\])?
```

---

<div class="post-metadata">

**Author:** ![Sameer\_Panicker](https://avatars.discourse-cdn.com/v4/letter/s/d9b06d/32.png) [@Sameer\_Panicker](https://discuss.elastic.co/u/Sameer_Panicker)\
**Post date:** [April 7, 2016, 4:49pm UTC](https://discuss.elastic.co/t/multiline-plugin-not-working-as-expected/46623/5 "2016-04-07T16:49:14Z")

</div>

Thanks for the reply Magnus.

I am stuck with 2 more issues. Added a topic but awaiting for reply. Is there any help that you can do here ?

Read logs stored using Enterprise Semantic Logging format -

> [@Read logs stored using Enterprise Semantic Logging format](https://discuss.elastic.co/t/read-logs-stored-using-enterprise-semantic-logging-format/46449/6):
>
> You need to look at this then - [https://www.elastic.co/guide/en/logstash/current/plugins-filters-multiline.html](https://www.elastic.co/guide/en/logstash/current/plugins-filters-multiline.html)

ssl\_certificate\_validation not working -

> [@Ssl\_certificate\_validation not working](https://discuss.elastic.co/t/ssl-certificate-validation-not-working/46304):
>
> ssl\_certificate\_validation =\> false is not working in HTTP\_Poller configuration. My service URL is HTTPS but there is no need to pass any certs along with the call. Hence, I wanted to skip it. Even with the above option enabled, it is checking for SSL certs. What can I do here ?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:03am UTC](https://discuss.elastic.co/t/multiline-plugin-not-working-as-expected/46623/6 "2017-07-06T05:03:14Z")

</div>


