# Want to extract the logs based on keyword

**URL:** <https://discuss.elastic.co/t/want-to-extract-the-logs-based-on-keyword/88810>\
**Category:** Logstash\
**Created:** [June 9, 2017, 9:02am UTC](https://discuss.elastic.co/t/want-to-extract-the-logs-based-on-keyword/88810 "2017-06-09T09:02:25Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![sanupam](https://avatars.discourse-cdn.com/v4/letter/s/a4c791/32.png) [@sanupam](https://discuss.elastic.co/u/sanupam)\
**Post date:** [June 9, 2017, 9:02am UTC](https://discuss.elastic.co/t/want-to-extract-the-logs-based-on-keyword/88810/1 "2017-06-09T09:02:25Z")

</div>

Hello,

I have a log below:

Jun 05, 2017 6:45:07 AM sai.pollers.SaiDbPollerServlet handleNotification  
INFO: msg ======== MapMessage[null]  
Jun 05, 2017 6:45:07 AM sai.mdb.framework.SaiMessageDrivenBean onMessage  
INFO: Enter sai.mdb.service.client.SynapseERPSesamOrderTrackingBean.onMessage()  
Jun 05, 2017 6:45:07 AM sai.pollers.SaiPollerServlet info  
INFO: SESAM0SYNAPSE\_QUOTE\_OPT248516965FI62604132248516965\<map

how to extract the logs based on the keywork "INFO:" and until it gets next "INFO:", all comes in a single message.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 9, 2017, 9:32am UTC](https://discuss.elastic.co/t/want-to-extract-the-logs-based-on-keyword/88810/2 "2017-06-09T09:32:43Z")

</div>

Have you looked at the multiline codec?

---

<div class="post-metadata">

**Author:** ![sanupam](https://avatars.discourse-cdn.com/v4/letter/s/a4c791/32.png) [@sanupam](https://discuss.elastic.co/u/sanupam)\
**Post date:** [June 11, 2017, 4:37pm UTC](https://discuss.elastic.co/t/want-to-extract-the-logs-based-on-keyword/88810/3 "2017-06-11T16:37:34Z")

</div>

Hi,

Yes I have tried the multiline coded but it doesn't work.

Can you please share the sample configuration file that search for keyword "Hello" in the logfile.

Regards,  
Anupam

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 12, 2017, 5:57am UTC](https://discuss.elastic.co/t/want-to-extract-the-logs-based-on-keyword/88810/4 "2017-06-12T05:57:33Z")

</div>

> Yes I have tried the multiline coded but it doesn't work.

What did you try?

> Can you please share the sample configuration file that search for keyword "Hello" in the logfile.

See [Accessing Event Data and Fields in the Configuration | Logstash Reference [5.4] | Elastic](https://www.elastic.co/guide/en/logstash/5.4/event-dependent-configuration.html).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 10, 2017, 5:57am UTC](https://discuss.elastic.co/t/want-to-extract-the-logs-based-on-keyword/88810/5 "2017-07-10T05:57:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
