# Problem with logstash config

**URL:** <https://discuss.elastic.co/t/problem-with-logstash-config/77275>\
**Category:** Logstash\
**Created:** [March 3, 2017, 6:45am UTC](https://discuss.elastic.co/t/problem-with-logstash-config/77275 "2017-03-03T06:45:45Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Artyom\_Davydov](https://avatars.discourse-cdn.com/v4/letter/a/8dc957/32.png) [@Artyom\_Davydov](https://discuss.elastic.co/u/Artyom_Davydov)\
**Post date:** [March 3, 2017, 6:45am UTC](https://discuss.elastic.co/t/problem-with-logstash-config/77275/1 "2017-03-03T06:45:46Z")

</div>

Hi all. We have trying to migrate our config (1.5) to newer (5.2) version of logstash . And we have some problem with multiline plugin. so here is an example of our config and log error.

> filter {  
> if [type] == "osb\_server" {  
> multiline {  
> pattern =\> "(^#)"  
> negate =\> true  
> what =\> "previous"  
> }  
> }  
> }

Error:

> [2017-03-03T09:44:13,539][ERROR][logstash.agent] Cannot load an invalid configuration {:reason=\>"Couldn't find any filter plugin named 'multiline'. Are you sure this is correct? Trying to load the multiline filter plugin resulted in this error: Problems loading the requested plugin named multiline of type filter. Error: NameError NameError"}  
> [2017-03-03T09:44:16,533][ERROR][logstash.plugins.registry] Problems loading a plugin with {:type=\>"filter", :name=\>"multiline", :path=\>"logstash/filters/multiline", :error\_message=\>"NameError", :error\_class=\>NameError, :error\_backtrace=\>["/usr/share/logstash/logstash-core/lib/logstash/plugins/registry.rb:221:in `namespace_lookup'", "/usr/share/logstash/logstash-core/lib/logstash/plugins/registry.rb:157:in `legacy\_lookup'", "/usr/share/logstash/logstash-core/lib/logstash/plugins/registry.rb:133:in `lookup'", "/usr/share/logstash/logstash-core/lib/logstash/plugins/registry.rb:175:in `lookup\_pipeline\_plugin'", "/usr/share/logstash/logstash-core/lib/logstash/plugin.rb:129:in `lookup'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:95:in `plugin'", "(eval):64:in `initialize'", "org/jruby/RubyKernel.java:1079:in `eval'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:65:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:308:in `reload\_pipeline!'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:111:in `reload_state!'", "org/jruby/RubyHash.java:1342:in `each'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:108:in `reload_state!'", "org/jruby/ext/thread/Mutex.java:149:in `synchronize'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:107:in `reload_state!'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:75:in `execute'", "org/jruby/RubyProc.java:281:in `call'", "/usr/share/logstash/vendor/bundle/jruby/1.9/gems/stud-0.0.22/lib/stud/interval.rb:20:in `interval'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:75:in `execute'", "/usr/share/logstash/logstash-core/lib/logstash/runner.rb:271:in `execute'", "org/jruby/RubyProc.java:281:in `call'", "/usr/share/logstash/vendor/bundle/jruby/1.9/gems/stud-0.0.22/lib/stud/task.rb:24:in `initialize'"]}  
> [2017-03-03T09:44:16,535][ERROR][logstash.agent] Cannot load an invalid configuration {:reason=\>"Couldn't find any filter plugin named 'multiline'. Are you sure this is correct? Trying to load the multiline filter plugin resulted in this error: Problems loading the requested plugin named multiline of type filter. Error: NameError NameError"}

Do we need to install filter plugin ? i think it goes from the box..

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 3, 2017, 6:46am UTC](https://discuss.elastic.co/t/problem-with-logstash-config/77275/2 "2017-03-03T06:46:24Z")

</div>

You need to change to the multiline codec instead.

---

<div class="post-metadata">

**Author:** ![Artyom\_Davydov](https://avatars.discourse-cdn.com/v4/letter/a/8dc957/32.png) [@Artyom\_Davydov](https://discuss.elastic.co/u/Artyom_Davydov)\
**Post date:** [March 3, 2017, 6:52am UTC](https://discuss.elastic.co/t/problem-with-logstash-config/77275/3 "2017-03-03T06:52:03Z")

</div>

thx for answer. we have changed and got this error.

> filter {  
> if [type] == "osb\_server" {  
> codec =\> multiline {  
> pattern =\> "(^#)"  
> negate =\> true  
> what =\> "previous"  
> }  
> }  
> }

Error:

> [2017-03-03T09:50:28,505][ERROR][logstash.agent] Cannot load an invalid configuration {:reason=\>"Expected one of #, { at line 27, column 13 (byte 320) after filter {\nif [type] == "osb\_server" {\n codec "}

In official manual use case is without codecs [Multiline codec plugin | Logstash Reference [8.11] | Elastic](https://www.elastic.co/guide/en/logstash/current/plugins-codecs-multiline.html)

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 3, 2017, 7:41am UTC](https://discuss.elastic.co/t/problem-with-logstash-config/77275/4 "2017-03-03T07:41:04Z")

</div>

Codecs are specified within the input plugin, not as a separate filter. Where are you getting your data from?

---

<div class="post-metadata">

**Author:** ![Artyom\_Davydov](https://avatars.discourse-cdn.com/v4/letter/a/8dc957/32.png) [@Artyom\_Davydov](https://discuss.elastic.co/u/Artyom_Davydov)\
**Post date:** [March 3, 2017, 7:57am UTC](https://discuss.elastic.co/t/problem-with-logstash-config/77275/5 "2017-03-03T07:57:34Z")

</div>

quote from manual:

> One more common example is C line continuations (backslash). Here’s how to do that:

> filter {  
> multiline {  
> type =\> "somefiletype"  
> pattern =\> "\$"  
> what =\> "next"  
> }  
> }

in 1.5 multiline was filter plugin?  
We are getting data from filebeats.  
example of our 1.5 ver config:

> input {  
> beats {  
> port =\> 5044  
> tags =\> "beats"  
> }  
> }  
> filter {
> 
> ### OSB\_SERVER type
> 
> if [type] == "osb\_server" {  
> multiline {  
> pattern =\> "(^#)"  
> negate =\> true  
> what =\> "previous"  
> }  
> }
> 
> ### _OSB_ type
> 
> if [type] =~ "osb" {  
> if [message] =~ "http:SOAPAction"SendVeterinaryPermit"\</http:SOAPAction\>" {  
> grok {  
> match =\> { "message" =\> "(?\<easu\_permit\_number\>.+)" }  
> }  
> }  
> if [message] =~ "" {  
> grok {  
> match =\> { "message" =\> "(?\<application\_status\>[^\<]+)" }  
> }  
> }

> ### OSB\_MLT\_\* type
> 
> if [type] =~ "osb\_mlt\_\*" {  
> multiline {  
> pattern =\> "^####\<"  
> negate =\> true  
> what =\> "previous"  
> }  
> }
> 
> ### SOA\_MLT\_\* type
> 
> if [type] =~ "soa\_mlt\_\*" {  
> multiline {  
> pattern =\> "^####\<"  
> negate =\> true  
> what =\> "previous"  
> }  
> }  
> and so on...  
> the output is to the gelf.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 3, 2017, 8:00am UTC](https://discuss.elastic.co/t/problem-with-logstash-config/77275/6 "2017-03-03T08:00:57Z")

</div>

The multiline filter plugin has been deprecated as it required a single worker thread and had problems with multiple inputs getting mixed. It is always recommended to perform multiline processing as close to the source as possible, so if you are using Filebeat, I would recommend to [move the multiline processing there](https://www.elastic.co/guide/en/beats/filebeat/5.2/multiline-examples.html) instead of using a codec in Logstash.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 31, 2017, 8:01am UTC](https://discuss.elastic.co/t/problem-with-logstash-config/77275/7 "2017-03-31T08:01:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
