# StackTrace with multiline filter on logstash

**URL:** <https://discuss.elastic.co/t/stacktrace-with-multiline-filter-on-logstash/91718>\
**Category:** Logstash\
**Created:** [July 4, 2017, 6:44am UTC](https://discuss.elastic.co/t/stacktrace-with-multiline-filter-on-logstash/91718 "2017-07-04T06:44:57Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Govind\_Raj](https://avatars.discourse-cdn.com/v4/letter/g/a88e57/32.png) [@Govind\_Raj](https://discuss.elastic.co/u/Govind_Raj)\
**Post date:** [July 4, 2017, 6:44am UTC](https://discuss.elastic.co/t/stacktrace-with-multiline-filter-on-logstash/91718/1 "2017-07-04T06:44:57Z")

</div>

hi

We user beats to send the logs to our centralized log server. We are finding it bit difficult to parse a stack trace . The sample log is below ,  
INFO 2017-07-02 03:46:52,714 [[corn-ice-1.0.0-SNAPSHOT].schedule-db\_flow.stage1.03] org.mule.api.processor.LoggerMessageProcessor: Failed to Run with this Query null, try after 10 seconds  
ERROR 2017-07-02 03:46:52,614 [[corn-ice-1.0.0-SNAPSHOT].schedule-db\_flow.stage1.16] org.mule.exception.CatchMessagingExceptionStrategy:

* * *

## Message : Incorrect integer value: 'null' for column 'event\_id' at row 1 (java.sql.SQLException). Message payload is of type: Schedule Code : MULE\_ERROR-29999

Exception stack is:

1. Incorrect integer value: 'null' for column 'event\_id' at row 1 (java.sql.SQLException)  
com.mysql.jdbc.SQLError:946 (null)
2. Incorrect integer value: 'null' for column 'event\_id' at row 1 (java.sql.SQLException). Message payload is of type: Schedule (org.mule.api.MessagingException)  
org.mule.module.db.internal.processor.AbstractDbMessageProcessor:93 ([http://www.mulesoft.org/docs/site/current3/apidocs/org/mule/api/MessagingException.html](http://www.mulesoft.org/docs/site/current3/apidocs/org/mule/api/MessagingException.html))

* * *

Root Exception stack trace:  
java.sql.SQLException: Incorrect integer value: 'null' for column 'event\_id' at row 1  
at com.mysql.jdbc.SQLError.createSQLException(SQLError.java:946)  
at com.mysql.jdbc.MysqlIO.checkErrorPacket(MysqlIO.java:2985)  
at com.mysql.jdbc.MysqlIO.sendCommand(MysqlIO.java:1631)  
+ 3 more (set debug level logging or '-Dmule.verbose.exceptions=true' for everything)

* * *

INFO 2017-07-02 03:46:52,614 [[corn-ice-1.0.0-SNAPSHOT].schedule-db\_flow.stage1.16] org.mule.api.processor.LoggerMessageProcessor: Failed to Run with this Query null, try after 10 seconds

we would like parse and push the log to ES only when the message has "Incorrect integer value: 'null' for column 'event\_id' " . Can some one help us with using multiline on logstash filter to process the same .  
any suggestion would be helpful

Thanks  
Raj

---

<div class="post-metadata">

**Author:** ![Govind\_Raj](https://avatars.discourse-cdn.com/v4/letter/g/a88e57/32.png) [@Govind\_Raj](https://discuss.elastic.co/u/Govind_Raj)\
**Post date:** [July 6, 2017, 8:20am UTC](https://discuss.elastic.co/t/stacktrace-with-multiline-filter-on-logstash/91718/2 "2017-07-06T08:20:32Z")

</div>

Found the solution my self with Elastic documentation and other blogs  
The multiline filter looks as follows  
multiline {  
patterns\_dir =\> "./patterns"  
pattern =\> "(^INFO)|(^ERROR)|(^WARN)"  
negate =\> true  
what =\> "previous"  
}

followed by simple grok to match the string we need to identify .

Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 3, 2017, 8:20am UTC](https://discuss.elastic.co/t/stacktrace-with-multiline-filter-on-logstash/91718/3 "2017-08-03T08:20:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
