# Parser fails when it encounters a newline / Parser falla cuando encuentra un salto de linea

**URL:** <https://discuss.elastic.co/t/parser-fails-when-it-encounters-a-newline-parser-falla-cuando-encuentra-un-salto-de-linea/365718>\
**Category:** Logstash\
**Created:** [August 28, 2024, 5:49pm UTC](https://discuss.elastic.co/t/parser-fails-when-it-encounters-a-newline-parser-falla-cuando-encuentra-un-salto-de-linea/365718 "2024-08-28T17:49:24Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Roberto\_Soto](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/roberto_soto/32/137125_2.png) [@Roberto\_Soto](https://discuss.elastic.co/u/Roberto_Soto)\
**Post date:** [August 28, 2024, 5:49pm UTC](https://discuss.elastic.co/t/parser-fails-when-it-encounters-a-newline-parser-falla-cuando-encuentra-un-salto-de-linea/365718/1 "2024-08-28T17:49:24Z")

</div>

hi, i have a problem when a ln or \n exist in message text. my filter grok is

match=\>{"message" =\> "\<%{DATA:timestamp}\> \<%{WORD:Severity}\> \<%{WORD:Subsystem}\> \<%{HOSTNAME:ServerName}\> \<%{HOSTNAME:Instancia}\> \<%{DATA:Thread}\> \<\<%{DATA:Kernel}\>\> \<%{DATA:UserId}\> \<%{NOTSPACE:MsgId}\> \<%{DATA:MsgText}\>"  
and work ok, but when field MsgText have a ln or \s fail.

Below, in the image of the weblogic log, after "java:726)" comes a line break and this causes the field reading to fail

 ![2024-08-28_13-45-53](https://us1.discourse-cdn.com/elastic/original/3X/7/d/7dd9cf00802edcde19cdb2f02538e8cc7b56ffc7.jpeg)

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 28, 2024, 6:21pm UTC](https://discuss.elastic.co/t/parser-fails-when-it-encounters-a-newline-parser-falla-cuando-encuentra-un-salto-de-linea/365718/2 "2024-08-28T18:21:34Z")

</div>

What does your event look like? Are you doing multiline processing? If so, is it in filebeat or are you using a multiline codec in logstash? The codec has an example in the [documentation](https://www.elastic.co/guide/en/logstash/current/plugins-codecs-multiline.html) of how to handle Java stack traces.

You need to provide more detail about your configuration. Get the entire message into a single event before you start worrying about how to configure the grok filter.

---

<div class="post-metadata">

**Author:** ![Roberto\_Soto](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/roberto_soto/32/137125_2.png) [@Roberto\_Soto](https://discuss.elastic.co/u/Roberto_Soto)\
**Post date:** [August 30, 2024, 3:05am UTC](https://discuss.elastic.co/t/parser-fails-when-it-encounters-a-newline-parser-falla-cuando-encuentra-un-salto-de-linea/365718/3 "2024-08-30T03:05:44Z")

</div>

thank you, i fixed it by changing the %{DATA:MsgText} field to (?(.|\r|\n)\*). With this change, the line breaks in the text are controlled
