# Unable parse multiline pattern

**URL:** <https://discuss.elastic.co/t/unable-parse-multiline-pattern/221043>\
**Category:** Logstash\
**Created:** [February 26, 2020, 12:41pm UTC](https://discuss.elastic.co/t/unable-parse-multiline-pattern/221043 "2020-02-26T12:41:13Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![bivaswap](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bivaswap/32/47121_2.png) [@bivaswap](https://discuss.elastic.co/u/bivaswap)\
**Post date:** [February 26, 2020, 12:41pm UTC](https://discuss.elastic.co/t/unable-parse-multiline-pattern/221043/1 "2020-02-26T12:41:14Z")

</div>

Hello,  
I am trying to parse multiline logs

Log sample

```
06/Feb/2020:09:20 +0000 ACCESS {
  "Total alerts subscribed for email only": 0,
  "Total alerts subscribed for In-App only": 59579

```

filebeat configuration

```
filebeat.inputs:
- type: log
  enabled: true
  paths:
    - /var/log/test.log
  multiline.pattern: '^[0-9]{1,3}'
  multiline.negate: true
  multiline.match: after
output.logstash:
  hosts: ["172.16.0.143:5044"]
processors:
  - add_cloud_metadata: ~

```

Logstash Configuration

```
input {
  beats {
    port => 5044
  }
}
filter {
  grok {
    match => {
      "message" => [
         "%{GREEDYDATA:[app][timestamp]} %{WORD:[app][loglevel]} \{%{SPACE}\"%{GREEDYDATA}\"\: %{NUMBER:[app][totalSubscribedNumber]}\,%{SPACE}\"%{GREEDYDATA}\"\: %{NUMBER:[app][totalSubscribedNumberInApp]}"
      ]
    }
  }
  mutate {
    remove_field => ["agent","[log][offset]","[cloud][account]","[cloud][region]","[cloud][machine]","[cloud][image]","[cloud][availability_zone]","[cloud][provider]"]
  }

}
output {
    stdout {
        codec => rubydebug
    }
}

```

Output

```
{
    "@timestamp" => 2020-02-26T12:24:58.674Z,
          "tags" => [
        [0] "beats_input_codec_plain_applied",
        [1] "_grokparsefailure"
    ],
          "host" => {
        "name" => "beats"
    },
       "message" => "06/Feb/2020:09:20 +0000 ACCESS {\n \"Total alerts subscribed for email only\": 0,\n \"Total alerts subscribed for In-App only\": 59579",
           "log" => {
        "flags" => [
            [0] "multiline"
        ],
         "file" => {
            "path" => "/var/log/test.log"
        }
    }
}

```

Note:

1. Parsing multiple pattern with same logstash, can't use multiline codec on logstash
2. Same pattern working perfectly fine with Kibana Grok Debugger & [https://grokdebug.herokuapp.com](https://grokdebug.herokuapp.com)
3. Filebeat & Logstash both are running with v7.6

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 26, 2020, 3:07pm UTC](https://discuss.elastic.co/t/unable-parse-multiline-pattern/221043/2 "2020-02-26T15:07:25Z")

</div>

Did you have a question?

---

<div class="post-metadata">

**Author:** ![bivaswap](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bivaswap/32/47121_2.png) [@bivaswap](https://discuss.elastic.co/u/bivaswap)\
**Post date:** [February 26, 2020, 3:25pm UTC](https://discuss.elastic.co/t/unable-parse-multiline-pattern/221043/3 "2020-02-26T15:25:49Z")

</div>

Sorry, I should have clearly mentioned.

I am trying to parse the above mentioned multiline log.  
Any help would be appreciated.

As far as I understood, logstash seeing the multiline logs in different way when it coming through filebeat.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 25, 2020, 3:25pm UTC](https://discuss.elastic.co/t/unable-parse-multiline-pattern/221043/4 "2020-03-25T15:25:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
