# Parsing multiline log: correct output in Logstash and error in kibana

**URL:** <https://discuss.elastic.co/t/parsing-multiline-log-correct-output-in-logstash-and-error-in-kibana/234411>\
**Category:** Logstash\
**Created:** [May 26, 2020, 7:52pm UTC](https://discuss.elastic.co/t/parsing-multiline-log-correct-output-in-logstash-and-error-in-kibana/234411 "2020-05-26T19:52:40Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![guas5](https://avatars.discourse-cdn.com/v4/letter/g/977dab/32.png) [@guas5](https://discuss.elastic.co/u/guas5)\
**Post date:** [May 26, 2020, 7:52pm UTC](https://discuss.elastic.co/t/parsing-multiline-log-correct-output-in-logstash-and-error-in-kibana/234411/1 "2020-05-26T19:52:40Z")

</div>

Hi everyone,

would be really gratefull for any ideas how to solve the following issue. I have defined a regex pattern for a multiline log and checked its output in Logstash, everything looks correct. But once I send data to ElasticSearch and create Kibana index pattern, I get "\_grokparsefailure" for the same data. My assumption is that in Logstash new line is separated with \r\n and when I check the same failure message in Kibana, new line is separated with \n. I compared this using GROK debugger in Kibana and there \n works and \r\n doesn't. I tried to include into the pattern condition (\r\n|\n) but it didn't work either. I have windows and need to extract the number at the end "TPP".  
Thanks for any ideas!  
Here is my code:

```auto
%{TIMESTAMP:ts} %{WORD:st} %{DATA:num} %{DATA:message_1} \- (?<message_2>[^\,]*)\((?<fieldname>[^)]*\)\,(\n|\r\n))\((?<fieldname1>[^)]*\)\,(\n|\r\n))\((?<fieldname2>[^)]*\)\,(\n|\r\n))\(%{WORD:fieldname3}\=%{NUMBER:TPP}

```

---

<div class="post-metadata">

**Author:** ![guas5](https://avatars.discourse-cdn.com/v4/letter/g/977dab/32.png) [@guas5](https://discuss.elastic.co/u/guas5)\
**Post date:** [May 29, 2020, 11:28am UTC](https://discuss.elastic.co/t/parsing-multiline-log-correct-output-in-logstash-and-error-in-kibana/234411/2 "2020-05-29T11:28:07Z")

</div>

Hi everyone! I managed to solve the issue, hope will be useful for somebody as well: I changed the Regex pattern and included \r\n into each feild during pasring. Worked out well!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 26, 2020, 11:28am UTC](https://discuss.elastic.co/t/parsing-multiline-log-correct-output-in-logstash-and-error-in-kibana/234411/3 "2020-06-26T11:28:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
