# Using Multiline to group events by number not by timestamp

**URL:** https://discuss.elastic.co/t/using-multiline-to-group-events-by-number-not-by-timestamp/62150
**Category:** Logstash
**Created:** [October 4, 2016, 11:18am UTC](https://discuss.elastic.co/t/using-multiline-to-group-events-by-number-not-by-timestamp/62150 "2016-10-04T11:18:13Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![9474](https://avatars.discourse-cdn.com/v4/letter/9/e68b1a/32.png) [@9474](https://discuss.elastic.co/u/9474)
#### Post date: [October 4, 2016, 11:18am UTC](https://discuss.elastic.co/t/using-multiline-to-group-events-by-number-not-by-timestamp/62150/1 "2016-10-04T11:18:13Z")

</div>

Hello,  
(Apologies for any faux pas but first time posting in any forum).

I'm pulling an event log stored in a table from an Oracle DB via a JDBC connection. A simplistic example of the data:

> EVENTID USER TYPE MESSAGE DATE  
> 1234 BOB LOGIN SUCCESS 4-OCT-2016 12:01:01  
> 1234 BOB BROWSER IE8 4-OCT-2016 12:01:01  
> 1235 JANE LOGIN SUCCESS 4-OCT-2016 12:01:01  
> 1235 JANE BROWSER IE8 4-OCT-2016 12:01:01

User BOB logs in at 12:01 on the 4th and uses IE8 to do so.  
User JANE logs in at 12:01 on the 4th and uses IE8 to do so also.

The column datatype in the Oracle table is DATE not TIMESTAMP so i don't have fractional seconds to separate out events, therefore i would like to use the EVENTID which will always be unique for each event.

I'm aiming to create a single document in Elasticsearch for each event like so;

> eventid:1234  
> userid:bob  
> type: login  
> result: success  
> browser: IE8  
> @timestamp: event date

During testing if i have one event in a table, with multiple rows, then my logstash conf works perfectly. It merges the multiline input from the JDBC and creates a single document as I expect. However when I have more than 1 event, like the data above, the multiline filter isn't breaking the input by the eventid, but taking everything as a single event, like so:

> "eventid" =\> [  
> [0] 1234,  
> [1] 1235  
> ...

Here is my multiline filter:

> multiline {  
> pattern =\> "^%{NUMBER}"  
> what =\> "next"  
> negate=\> true  
> allow\_duplicates =\> false  
> }

All of the examples online use multiline with a timestamp and the following lines are preceded by white space or something equally easy to handle.

So my questions is:  
How do I get the multiline filter or codec to group lines by the eventid _value_, not just the _pattern of the value_.

Many thanks for making the time to read, I hope you can help.

Regards,

James

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [October 9, 2016, 2:34pm UTC](https://discuss.elastic.co/t/using-multiline-to-group-events-by-number-not-by-timestamp/62150/2 "2016-10-09T14:34:11Z")

</div>

The multiline codec or filter is the wrong tool for this. Have a look at the aggregate or collate filters instead.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 6, 2017, 4:35am UTC](https://discuss.elastic.co/t/using-multiline-to-group-events-by-number-not-by-timestamp/62150/3 "2017-07-06T04:35:00Z")

</div>


