# Mysql-slow multiline

**URL:** <https://discuss.elastic.co/t/mysql-slow-multiline/277757>\
**Category:** Logstash\
**Created:** [July 5, 2021, 2:17am UTC](https://discuss.elastic.co/t/mysql-slow-multiline/277757 "2021-07-05T02:17:09Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![bz\_Os](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bz_os/32/90863_2.png) [@bz\_Os](https://discuss.elastic.co/u/bz_Os)\
**Post date:** [July 5, 2021, 2:17am UTC](https://discuss.elastic.co/t/mysql-slow-multiline/277757/1 "2021-07-05T02:17:09Z")

</div>

Hello,

I am parsing the mysql-slow logs using the parser:

> ```auto
> input{
> pipeline {
> address => input
> }
> file{
> path => "/etc/logstash/logsamples/all.log"
> start_position => "beginning"
> sincedb_path => "/dev/null"
> codec => multiline {
> pattern => "^ # User @ Host:"
> negate => true
> what => "previous"
> }
> }
> }
> 
> filter{
> grok{
> match => {"message" =>"%{SYSLOGBASE2}%{GREEDYDATA:mess}"}
> pattern_definitions => {
> "GREEDYMULTILINE" => "(\r|\n)*"
> }
> }
> }
> 
> ```

As result i get all the logs bellow as one line and not multiline.

> Jun 1 01:01:58 mypc mysql-slow: # Time: 210601 1:01:58  
> Jun 1 01:01:58 mypc mysql-slow: # User@Host: fp[fp] @ [10.64.5.169]  
> Jun 1 01:01:58 mypc mysql-slow: # Thread\_id: 91926893 Schema: oli QC\_hit: No  
> Jun 1 01:01:58 mypc mysql-slow: # Query\_time: 2.769906 Lock\_time: 0.000126 Rows\_sent: 0 Rows\_examined: 14893  
> Jun 1 01:01:58 mypc mysql-slow: # Rows\_affected: 0  
> Jun 1 01:01:58 mypc mysql-slow: SET timestamp=1622502118;  
> Jun 1 01:01:58 mypc mysql-slow: SELECT id, amount  
> Jun 1 01:01:58 mypc mysql-slow: FROM dbo  
> Jun 1 01:01:58 mypc mysql-slow: WHERE  
> Jun 1 01:01:58 mypc mysql-slow: idOperationType = '4'  
> Jun 1 01:01:58 mypc mysql-slow: AND idAccount = '228'  
> Jun 1 01:01:58 mypc mysql-slow: AND receiveDate \>= '2021-05-31 00:00:00'  
> Jun 1 01:01:58 mypc mysql-slow: AND receiveDate \< '2021-06-01 00:00:00'  
> Jun 1 01:01:58 mypc mysql-slow: AND bk IN ('9','2');  
> Jun 1 01:02:13 mypc mysql-slow: # Time: 210601 1:02:12  
> Jun 1 01:02:13 mypc mysql-slow: # User@Host: fp[fp] @ [10.64.5.169]  
> Jun 1 01:02:13 mypc mysql-slow: # Thread\_id: 91926889 Schema: lifa3 QC\_hit: No  
> Jun 1 01:02:13 mypc mysql-slow: # Query\_time: 2.898778 Lock\_time: 0.000064 Rows\_sent: 0 Rows\_examined: 21134  
> Jun 1 01:02:13 mypc mysql-slow: # Rows\_affected: 0  
> Jun 1 01:02:13 mypc mysql-slow: use lifa3;  
> Jun 1 01:02:13 mypc mysql-slow: SET timestamp=1622502132;  
> Jun 1 01:02:13 mypc mysql-slow: SELECT id, amount  
> Jun 1 01:02:13 mypc mysql-slow: FROM dbo  
> Jun 1 01:02:13 mypc mysql-slow: WHERE  
> Jun 1 01:02:13 mypc mysql-slow: idOperationType = '4'  
> Jun 1 01:02:13 mypc mysql-slow: AND idAccount = '321'  
> Jun 1 01:02:13 mypc mysql-slow: AND receiveDate \>= '2021-05-31 00:00:00'  
> Jun 1 01:02:13 mypc mysql-slow: AND receiveDate \< '2021-06-01 00:00:00'  
> Jun 1 01:02:13 mypc mysql-slow: AND bk IN ('9','2');

can you please help me to solve the issue?

Best regards

---

<div class="post-metadata">

**Author:** ![bz\_Os](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bz_os/32/90863_2.png) [@bz\_Os](https://discuss.elastic.co/u/bz_Os)\
**Post date:** [July 6, 2021, 9:15pm UTC](https://discuss.elastic.co/t/mysql-slow-multiline/277757/2 "2021-07-06T21:15:58Z")

</div>

Hello expert,

do you have any proposals to solve the issue.

Best regards,

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 6, 2021, 9:40pm UTC](https://discuss.elastic.co/t/mysql-slow-multiline/277757/3 "2021-07-06T21:40:34Z")

</div>

> [@bz\_Os](#):
>
> `pattern => "^ # User @ Host:"`

I am surprised you get anything at all. That pattern does not appear in your logs, so it should read the entire file as one event which never gets flushed, because it only gets flushed when that pattern matches.

If you log entries look like

```
Jun 1 01:02:13 mypc mysql-slow: # User@Host: fp[fp] @ [10.64.5.169]

```

then change the pattern to `pattern => "# User@Host: "` (unanchored). You may also want to add `auto_flush_interval => 2` to the codec.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 3, 2021, 9:41pm UTC](https://discuss.elastic.co/t/mysql-slow-multiline/277757/4 "2021-08-03T21:41:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
