# Need help with Parsing Multiline StackTrace

**URL:** <https://discuss.elastic.co/t/need-help-with-parsing-multiline-stacktrace/188573>\
**Category:** Logstash\
**Created:** [July 2, 2019, 7:13pm UTC](https://discuss.elastic.co/t/need-help-with-parsing-multiline-stacktrace/188573 "2019-07-02T19:13:05Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![dips](https://avatars.discourse-cdn.com/v4/letter/d/c6cbf5/32.png) [@dips](https://discuss.elastic.co/u/dips)\
**Post date:** [July 2, 2019, 7:13pm UTC](https://discuss.elastic.co/t/need-help-with-parsing-multiline-stacktrace/188573/1 "2019-07-02T19:13:05Z")

</div>

Hello everyone, I am trying to parse multiline stack trace log file through logstash and am trying to figure out how to get this log file to load properly in elastic search.

My logstash.conf file:

```auto
input{

   file{

        path => "/home/Desktop/LogFiles/test_logs.log"

        sincedb_path => "/dev/null"

        start_position => "beginning"

        codec => multiline {

                pattern => "^\s"

                negate => true

                what => "previous"

        }

 }

}

filter{

if "server_crash" in [tag]{

        grok{

         break_on_match => false

         #Server_crash log parsing

         match => { "message" => "(?m)(?<ErrorMessage>[a-zA-Z$_0-9 \S]*)\s*(?<StackTrace>(.|\r|\n)*)"}

         match => { "message" => "(?m)(?<ErrorMessage>[a-zA-Z$_0-9 \S]*)\s*(?<StackTrace>(.|\r|\n)*)\n(?<Caused By>.*?Exception: .*+\n(\sat.*+\n)*+)"}

        }

        date{

         match => ["Timestamp", "UNIX_MS"]

         target => "@time"

        }

        }

}

```

Here is how my log file looks like:

```auto
util$failure: Exception thrown during the process{f6d4402 4777/u0a125}
	at util.Log(Log.java:295)
	at util.Slow(java:116)
	at com.attachApplicationLocked(java:6729)
	at com.Application(java:6821)
	at onTransact(java:539)
	at com.Transact(java:2844)
	at execTrans(565)
Caused by: DeadObjectException
	at transactNative(Native Method)
	at java:615
	at caution(Application.java)
	at com.Locked(ice.java)
	... 1 more​

```

With this, I restarted logstash service but data got ingested in the elasticsearch not as multiline but every line independently. How can I make it multiline? Am I missing something in the config file? Please advise.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 2, 2019, 7:23pm UTC](https://discuss.elastic.co/t/need-help-with-parsing-multiline-stacktrace/188573/2 "2019-07-02T19:23:31Z")

</div>

Change negate=\> true to negate =\> false. If you add auto\_flush\_interval then you will get 2 events

```
   "message" => "util$failure: Exception thrown during the process{f6d4402 4777/u0a125}\n at util.Log(Log.java:295)\n at util.Slow(java:116)\n at com.attachApplicationLocked(java:6729)\n at com.Application(java:6821)\n at onTransact(java:539)\n at com.Transact(java:2844)\n at execTrans(565)",
   "message" => "Caused by: DeadObjectException\n at transactNative(Native Method)\n at java:615\n at caution(Application.java)\n at com.Locked(ice.java)\n ... 1 more​",

```

If you do not have auto\_flush\_interval you will never see the second event, because flushing an event to the pipeline is triggered by a line that does not start with whitespace.

---

<div class="post-metadata">

**Author:** ![dips](https://avatars.discourse-cdn.com/v4/letter/d/c6cbf5/32.png) [@dips](https://discuss.elastic.co/u/dips)\
**Post date:** [July 2, 2019, 9:26pm UTC](https://discuss.elastic.co/t/need-help-with-parsing-multiline-stacktrace/188573/3 "2019-07-02T21:26:53Z")

</div>

Thanks Badger...Exactly what I was looking for.

---

<div class="post-metadata">

**Author:** ![dips](https://avatars.discourse-cdn.com/v4/letter/d/c6cbf5/32.png) [@dips](https://discuss.elastic.co/u/dips)\
**Post date:** [July 3, 2019, 6:15pm UTC](https://discuss.elastic.co/t/need-help-with-parsing-multiline-stacktrace/188573/4 "2019-07-03T18:15:15Z")

</div>

One quick question:  
I want to parse not only multiline stack trace logs files but also regular log files with single line parsing. I have changed path form input file as \*.log.

So now my one log file looks like:

```auto
util$failure: Exception thrown during the process{f6d4402 4777/u0a125}
	at util.Log(Log.java:295)
	at util.Slow(java:116)
	at com.attachApplicationLocked(java:6729)
	at com.Application(java:6821)
	at onTransact(java:539)
	at com.Transact(java:2844)
	at execTrans(565)
Caused by: DeadObjectException
	at transactNative(Native Method)
	at java:615
	at caution(Application.java)
	at com.Locked(ice.java)
	... 1 more​

```

and other log file looks like:

```auto
08-31 11:11:23 I/setupconnection( 352233): connecting...
08-31 11:11:12.129 I/setupconnection( 393221): disconnecting...
08-31 11:11:33.345 I/serveside(29203): system server!
08-31 11:11:33.472 D/callback(29203): callbutInstance: null
08-31 11:11:33.489 I/manager(29203): Starting Installer
08-31 11:11:33.494 I/caretaker(29203): Waiting for server to be ready

```

If I use below mentioned input, then only some of the multiline log files are parsed but now its ignoring regular log file. What am I doing wrong?

```auto
input{

   file{

        path => "/home/Desktop/LogFiles/*.log"

        sincedb_path => "/dev/null"

        start_position => "beginning"

        codec => multiline {

                pattern => "^\s"

                negate => false

                what => "previous"
                auto_flush_interval => 1

        }

 }

}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 3, 2019, 6:23pm UTC](https://discuss.elastic.co/t/need-help-with-parsing-multiline-stacktrace/188573/5 "2019-07-03T18:23:07Z")

</div>

I would expect that to work just fine with the log file that does not have leading whitespace.

Can you enable '--log.level trace' on the command line and see what filewatch says about that file?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 31, 2019, 6:23pm UTC](https://discuss.elastic.co/t/need-help-with-parsing-multiline-stacktrace/188573/6 "2019-07-31T18:23:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
