# Pipe to pipe with multiline codec on the second pipe

**URL:** <https://discuss.elastic.co/t/pipe-to-pipe-with-multiline-codec-on-the-second-pipe/295456>\
**Category:** Logstash\
**Created:** [January 26, 2022, 1:42pm UTC](https://discuss.elastic.co/t/pipe-to-pipe-with-multiline-codec-on-the-second-pipe/295456 "2022-01-26T13:42:36Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![John\_Smith1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/john_smith1/32/78332_2.png) [@John\_Smith1](https://discuss.elastic.co/u/John_Smith1)\
**Post date:** [January 26, 2022, 1:42pm UTC](https://discuss.elastic.co/t/pipe-to-pipe-with-multiline-codec-on-the-second-pipe/295456/1 "2022-01-26T13:42:36Z")

</div>

It's seems impossible, but just in case want to ask, is there some way to apply multiline code plugin in the second pipe, that receive logs from first pipe.  
first pipe pipe\_01.conf output:  
` pipeline { send_to => "pipe_2" codec => plain }`

second pipe pipe\_02.conf input:  
`pipeline { address => "pipe_2" }`

can we apply multiline code plugin in the second pipe?  
Thank you.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [January 26, 2022, 1:48pm UTC](https://discuss.elastic.co/t/pipe-to-pipe-with-multiline-codec-on-the-second-pipe/295456/2 "2022-01-26T13:48:43Z")

</div>

I don't think it is possible, the `pipeline` only have the configuration options of `send_to` and `address`.

You can check the [code](https://github.com/elastic/logstash/blob/55e7a2641616b6c94e1390a6a921b54650ecd5a3/logstash-core/lib/logstash/plugins/builtin/pipeline/input.rb#L21-L24) and you will see that for the input, the only config that exists is `address`.

I tried it once and it doesn't start if you use a codec, I ended up using an `udp`output and input.

---

<div class="post-metadata">

**Author:** ![John\_Smith1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/john_smith1/32/78332_2.png) [@John\_Smith1](https://discuss.elastic.co/u/John_Smith1)\
**Post date:** [January 26, 2022, 2:00pm UTC](https://discuss.elastic.co/t/pipe-to-pipe-with-multiline-codec-on-the-second-pipe/295456/3 "2022-01-26T14:00:07Z")

</div>

ok thank you. Anyway It was worth a shot to ask.  
Maybe there is workaround way to send logs from one to other pipe?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [January 26, 2022, 2:29pm UTC](https://discuss.elastic.co/t/pipe-to-pipe-with-multiline-codec-on-the-second-pipe/295456/4 "2022-01-26T14:29:32Z")

</div>

If you use the `pipeline` input and output, you only have the `send_to` and `address` option, you can't use any codec.

Why do you need a multiline codec in the destination pipeline? Can you give an example of what you are doing?

---

<div class="post-metadata">

**Author:** ![John\_Smith1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/john_smith1/32/78332_2.png) [@John\_Smith1](https://discuss.elastic.co/u/John_Smith1)\
**Post date:** [January 26, 2022, 2:51pm UTC](https://discuss.elastic.co/t/pipe-to-pipe-with-multiline-codec-on-the-second-pipe/295456/5 "2022-01-26T14:51:33Z")

</div>

I want to apply multiline codec to postfix documents. Main problem is that this postfix id that I use in pattern part of the multiline, could be in the different parts of document - sometimes it's in the beginning, sometimes in the end, or between names of directories and so on, so I can't just use something like ^%{POSTFIX\_ID} or $%{POSTFIX\_ID}. I tried to use just pattern %{POSTFIX\_ID} without setting place, but sometimes it triggers on the wrong values, therefore it need some anchor, so it triggers only when it's postfix id, and not something else, but anchor doesn't work too (since we can't set something like (%{POSTFIX\_ID}:|%{POSTFIX\_ID}.) , tried, wrong result).  
So I thought to sent documents to one pipe, get postfix id in first pipe, then set postfix id in the right place of the message and send it to the second pipe, in the second pipe logs will be processed with multiline codec plugin.  
(of course between documents with postfix id, there are documents without it, that's why I use multiline.)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 23, 2022, 2:52pm UTC](https://discuss.elastic.co/t/pipe-to-pipe-with-multiline-codec-on-the-second-pipe/295456/6 "2022-02-23T14:52:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
