# No output when using multiline codec from stdin

**URL:** <https://discuss.elastic.co/t/no-output-when-using-multiline-codec-from-stdin/73547>\
**Category:** Logstash\
**Created:** [February 1, 2017, 4:14pm UTC](https://discuss.elastic.co/t/no-output-when-using-multiline-codec-from-stdin/73547 "2017-02-01T16:14:42Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![mhooper](https://avatars.discourse-cdn.com/v4/letter/m/5e9695/32.png) [@mhooper](https://discuss.elastic.co/u/mhooper)\
**Post date:** [February 1, 2017, 4:14pm UTC](https://discuss.elastic.co/t/no-output-when-using-multiline-codec-from-stdin/73547/1 "2017-02-01T16:14:43Z")

</div>

I have recently started using logstash and am trying to build a sandbox environment to test different parsing.

I have built a test.config file using stdin and cat a data file through it to get stdout display of outcome. Using the same data file I get output (although not knowing of multiline) when input codec of multline is removed and I get no output when it is in config.

Config file  
input { stdin { codec =\> multiline { pattern =\> "^%{TIMESTAMP\_ISO8601} " negate =\> "true" what =\> "previous" } } }

output { stdout { codec =\> rubydebug } }

filter {  
grok {  
match =\> { "message" =\> "%{TIMESTAMP\_ISO8601:sourceTimestamp} [%{NUMBER:threadId}] %{LOGLEVEL:level} %{GREEDYDATA:tempMessage}" }  
add\_field =\> ["received\_at", "%{@timestamp}"]  
add\_field =\> ["received\_from", "%{host}"]  
}  
date {  
match =\> ["sourceTimestamp", "yyyy-MM-dd HH:mm:ss,SSS"]  
}  
if [source] =~ /core1ui1/ or [source] =~ /core1ui2/ {  
mutate {  
add\_tag =\> ["WebService"]  
}  
}  
}

Data being cat'ed into logstash.  
2017-02-01 08:00:00,114 [126925] DEBUG FixedSqlMembershipProvider - Executing command: Type=StoredProcedure  
-- begin statement parameters

---

<div class="post-metadata">

**Author:** ![sayalee](https://avatars.discourse-cdn.com/v4/letter/s/ecccb3/32.png) [@sayalee](https://discuss.elastic.co/u/sayalee)\
**Post date:** [February 2, 2017, 12:27pm UTC](https://discuss.elastic.co/t/no-output-when-using-multiline-codec-from-stdin/73547/2 "2017-02-02T12:27:34Z")

</div>

Can you try removing the double quotes from negate line in multiline filter ie., negate =\> true

---

<div class="post-metadata">

**Author:** ![mhooper](https://avatars.discourse-cdn.com/v4/letter/m/5e9695/32.png) [@mhooper](https://discuss.elastic.co/u/mhooper)\
**Post date:** [February 2, 2017, 12:44pm UTC](https://discuss.elastic.co/t/no-output-when-using-multiline-codec-from-stdin/73547/3 "2017-02-02T12:44:40Z")

</div>

That was originally how I had it and it didn't work, so I searched a few suggestions that said quotes might fix it. With or without double quotes, still no output.  
thanks for the suggestion .

---

<div class="post-metadata">

**Author:** ![sayalee](https://avatars.discourse-cdn.com/v4/letter/s/ecccb3/32.png) [@sayalee](https://discuss.elastic.co/u/sayalee)\
**Post date:** [February 2, 2017, 4:44pm UTC](https://discuss.elastic.co/t/no-output-when-using-multiline-codec-from-stdin/73547/4 "2017-02-02T16:44:06Z")

</div>

Can you send the sample log file if possible.

---

<div class="post-metadata">

**Author:** ![mhooper](https://avatars.discourse-cdn.com/v4/letter/m/5e9695/32.png) [@mhooper](https://discuss.elastic.co/u/mhooper)\
**Post date:** [February 2, 2017, 5:04pm UTC](https://discuss.elastic.co/t/no-output-when-using-multiline-codec-from-stdin/73547/5 "2017-02-02T17:04:58Z")

</div>

2017-02-01 08:00:00,114 [126925] DEBUG FixedSqlMembershipProvider - Executing command: Type=StoredProcedure  
-- begin statement parameters

---

<div class="post-metadata">

**Author:** ![sayalee](https://avatars.discourse-cdn.com/v4/letter/s/ecccb3/32.png) [@sayalee](https://discuss.elastic.co/u/sayalee)\
**Post date:** [February 3, 2017, 6:50am UTC](https://discuss.elastic.co/t/no-output-when-using-multiline-codec-from-stdin/73547/6 "2017-02-03T06:50:10Z")

</div>

Your .conf file is proper, I guess for testing purpose you are using only one entry in the log file try it with multiple entries, you will be able to see the output on stdout.

---

<div class="post-metadata">

**Author:** ![mhooper](https://avatars.discourse-cdn.com/v4/letter/m/5e9695/32.png) [@mhooper](https://discuss.elastic.co/u/mhooper)\
**Post date:** [February 3, 2017, 1:14pm UTC](https://discuss.elastic.co/t/no-output-when-using-multiline-codec-from-stdin/73547/7 "2017-02-03T13:14:11Z")

</div>

Thanks sayalee, you are correct. Although my original test was 2 log lines, it was 1 multi line and I assumed EOF would trigger output. Adding a dummy line in that closed the multi line triggered output of first occurrence.

thanks again

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 3, 2017, 1:14pm UTC](https://discuss.elastic.co/t/no-output-when-using-multiline-codec-from-stdin/73547/8 "2017-03-03T13:14:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
